Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cmedina33
Explorer

Site to Site VPN(Route Based) between two clusters

Hello,

Currently trying to bring up a route based S2S VPN between my two sites which each has 2 GW  in ClusterXL each and if it's possible your help on confirming this design.

This is based on this reference, but it kinda threw me off:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topi...

 

Also, I'm planning to use static routes, not dynamic routing. So, what's the next hop supposed to be?

I've attached a HLD for a better view of I think I'm supposed to configure.

 

PS: I've already configured VPN Community and a VPN Domain with an Empty Group as required.

Thanks!

 

0 Kudos
3 Replies
the_rock
Legend
Legend

So what exactly is failing? Do you see phase 1 and 2 completing?

Andy

0 Kudos
cmedina33
Explorer

Nothing is failing since I haven't completed the config. My question is specifically regarding the VTIs when GWs are clustered. Please see the attached HLD. 

ClusterA          ClusterB 

Gw1>>>>>>>>>>Gw1

Gw2>>>>>>>>>>Gw2

0 Kudos
the_rock
Legend
Legend

Ok, got it. Check out my post below about how this should be configured, though its with Azuire, its similar.

Andy

https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emc...

If still not clear, let me know.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events