- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi Mates,
I have a question regarding the setup of a Site-to-Site VPN between a Check Point cluster and two Cato peers with redundancy.
What is the best way to configure this scenario to ensure proper redundancy and failover between the two peers? Thanks
Hello
the best solution is to use route based vpn with dynamic routing protocol like BGP.
Hi Simone,
Is it also possible to achieve this using MEP, with the center gateways acting as the peer gateways? And in satellite gateways my checkpoint cluster?
MEP is only available between Check Point gateways.
I'm pretty sure that Cato support VPN route-based with BGP (or eventually static routing); I found a documentation page from Cato official site related to VPN between AWS gateway with redundancy.
Usually if you need redundancy, the best solution (adopted also by cloud provider, Harmony SASE, etc.) is route based vpn with routing protocol.
hi simone,
so i need to create VTI for this right?
Yes, you should create 2 VTIs numbered
We also need to configure two networks between the Check Point cluster and the remote peers (e.g., 169.254.x.x), one for each tunnel, and then set up the routing accordingly, right?
Yes you're right.
Have you already configured a route based vpn in the past?
Yes, with AWS the usually provide a file with all the steps to follow, while in this case we don’t have it, which is why I’m asking.
At this point, we also need to inform the other side that we are going to set up a VTI tunnel, since they will need to configure the corresponding networks (169.254.x.x) accordingly as well. Am I right?
Yes, you're right.
AWS provide a TXT file with all the configuration you need to apply, but the steps are the same for every route-based vpn.
Also reported in the admin guide: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/T...
Alright, thanks Simone. I just wanted to make sure my thought process was correct. Thank you for your support!
Hi Simone,
Only for info, i've checked the documentation related to MEP configuration and it seemes to be applied also for 3rd party Gateways:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VP...
MEP is implemented using RDP for Check Point Security Gateways and DPD for 3rd party Gateways / Cloud vendors.
Ok, good to know, I never used DPD for this purpose and, in addition, I don't trust DPD; I've always used Router-based vpn and BGP to implement VPN redundancy, for me is more standard and manageable.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 18 | |
| 15 | |
| 12 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY