- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Mates,
I have a question regarding the setup of a Site-to-Site VPN between a Check Point cluster and two Cato peers with redundancy.
What is the best way to configure this scenario to ensure proper redundancy and failover between the two peers? Thanks
Hello
the best solution is to use route based vpn with dynamic routing protocol like BGP.
Hi Simone,
Is it also possible to achieve this using MEP, with the center gateways acting as the peer gateways? And in satellite gateways my checkpoint cluster?
MEP is only available between Check Point gateways.
I'm pretty sure that Cato support VPN route-based with BGP (or eventually static routing); I found a documentation page from Cato official site related to VPN between AWS gateway with redundancy.
Usually if you need redundancy, the best solution (adopted also by cloud provider, Harmony SASE, etc.) is route based vpn with routing protocol.
hi simone,
so i need to create VTI for this right?
Yes, you should create 2 VTIs numbered
We also need to configure two networks between the Check Point cluster and the remote peers (e.g., 169.254.x.x), one for each tunnel, and then set up the routing accordingly, right?
Yes you're right.
Have you already configured a route based vpn in the past?
Yes, with AWS the usually provide a file with all the steps to follow, while in this case we don’t have it, which is why I’m asking.
At this point, we also need to inform the other side that we are going to set up a VTI tunnel, since they will need to configure the corresponding networks (169.254.x.x) accordingly as well. Am I right?
Yes, you're right.
AWS provide a TXT file with all the configuration you need to apply, but the steps are the same for every route-based vpn.
Also reported in the admin guide: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/T...
Alright, thanks Simone. I just wanted to make sure my thought process was correct. Thank you for your support!
Hi Simone,
Only for info, i've checked the documentation related to MEP configuration and it seemes to be applied also for 3rd party Gateways:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VP...
MEP is implemented using RDP for Check Point Security Gateways and DPD for 3rd party Gateways / Cloud vendors.
Ok, good to know, I never used DPD for this purpose and, in addition, I don't trust DPD; I've always used Router-based vpn and BGP to implement VPN redundancy, for me is more standard and manageable.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY