- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Dear Mates,
I am exploring VPN labs, where I want to do VPN redundancy configuration.
In detail,
SG1 and SG2 are Checkpoint devices.
I have configured Route based VPN between two SG1 and SG2 using ISP-1 IP address.
I have two ISP(external) interfaces for example ISP-1 and ISP-2 in each gateway and ISP redundancy is configured where VPN traffic is enabled in ISP configuration.
For example ISP-1 is down or no-link status in SG1 but in SG2 both links are UP, I want to connect the VPN between SG1 and SG2 with out interruption.
I have tried to give High Availability in Link selection mode but still Unable to connect.
So, can you please suggest or provide any sk/document for configuration.
Regards,
Saranya
Enhanced Link selection with R82 might be an option for you:
Apart from what Chris said, if you use legacy VRPN, you need to make sure proper routes are present in case of link failure.
Enhanced Link selection with R82 might be an option for you:
Dear Mates,
I have created Mesh topology successfully in lab.
I have seen in document that VPN Interoperability not supported for Quantum Spark Appliance.
Can I configure VPN redundancy with star topology between a Quantum Enterprise Appliance and a Quantum Spark Appliance, with the Quantum Enterprise acting as the central gateway, when both are managed by the same Management Server?
or
If Quantum Spark Appliance is not supported for VPN redundancy is there any other way?
Thank you for guidance.
Regards,
Saranya
Yes, more advanced topologies may required SD-WAN.
R82.00.10 may also bring some relevant improvements for Spark.
For VPN redundancy in Quantum Spark which are R81.10.XX firmware we need to configure SD-WAN.
For Quantum Enterprise Appliance static/dynamic routing protocol will work.
Is my understanding correct? Please correct if I am mistaken in my understanding.
Regards
Saranya
Not exactly, configuring static / dynamic routing has little to do with the choice of ISP used as the source (peer).
Case in point Spark appliances support route based VPNs (VTI) or MEP just fine to my knowledge.
SD-WAN is just an option, a good one (but requires a license).
in order to have SD-WAN overlay between two VPN peers, both sides have to be enabled with Quantum SD-WAN and managed from the same MGMT/MDS.
for no interruption at all, Quantum SD-WAN is the way to go.
you can use either Domain or Route based VPN based on your needs. VPN Redundancy over multiple ISPs will work regardless by the SD-WAN.
I would agree with that.
Apart from what Chris said, if you use legacy VRPN, you need to make sure proper routes are present in case of link failure.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY