Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saranya_0305
Collaborator

VPN Redundancy and SIC Failover Issues in Multi-Site Check Point Deployment

Dear Mates,

I have Management Server running on R82 managing the 1 Enterprise Appliance, 7 Quantum Spark appliances and 2 AWS Cloudguard Firewalls.

The Management Server and Enterprise firewall are in Same location and Management Server is behind the Enterprise Firewall and Management have specific NATed IP and
remaining firewalls are in different locations .

Each firewalls has 2 Individual ISP connected with ISP redundancy configuration except Cloudguard Firewalls.

All 7 Quantum Spark Firewalls are connected to Management Server(SIC) using ISP Ip of firewalls as that Ips are shown in Smartconsole.

And I have mesh topology Route based VPN configured among all of the firewall.

The ISP redundancy is working well in all locations.

But the VPN redundancy is not working properly, below is the usecases.

1) When at Enterprise Firewall,if ISP-1 fails, the traffic is shifted to ISP-2 but the VPN tunnels are down to Quantum Spark firewalls, but after some time(approx 1.30 min) they automatically working except to Cloudguard firewall.

2) When at Enterprise Firewall,if ISP-1 fails, the traffic is shifted to ISP-2 but SIC is breaking to Quantum Spark firewalls even both ISP are fine at Quantum Spark side.When we check the route to Management Server route is showing via VPN tunnel.(Management is included in VPN domain)

My queries are

1) Why the tunnels quantum spark VPN takes much time to work properly and why Cloudguard is not working?
2) As per my understanding we will establish the SIC first and we will create VPN. Then why the SIC traffic is going via VPN tunnel and why SIC breaks even though the Quantum Spark appiance both ISP are up and working.?

 

Regards,

Saranya

0 Kudos
2 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Best practice is to ensure SIC communication is outside the VPN.

How is your NAT for the Management configured is the IP specific to ISP-1 vs ISP-2?

You've deliberately put the public NAT address for Management in the VPN domain or has the Spark reverted to trying to reach the internal address? 

CCSM R77/R80/ELITE
0 Kudos
Saranya_0305
Collaborator

The Management NATed IP not related to both ISPs it is seperate Public IP.

The private IP of Mangement is in VPN domian not Public IP.

 

Regards,

Saranya

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events