Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saranya_0305
Collaborator
Jump to solution

VPN Redundancy b/w two Gateways

Dear Mates,

I am exploring VPN labs, where I want to do VPN redundancy configuration.

In detail,

SG1 and SG2 are Checkpoint devices.

I have configured Route based VPN between two SG1 and SG2 using ISP-1 IP address.

I have two ISP(external) interfaces for example ISP-1 and ISP-2 in each gateway and ISP redundancy is configured where VPN traffic is enabled in ISP configuration.

For example ISP-1 is down or no-link status in SG1 but in SG2 both links are UP, I want to connect the VPN between SG1 and SG2 with out interruption.

I have tried to give High Availability in Link selection mode but still Unable to connect.

So, can you please suggest or provide any sk/document for configuration.

 

Regards,
Saranya

0 Kudos
2 Solutions

Accepted Solutions
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP
the_rock
MVP Platinum
MVP Platinum

Apart from what Chris said, if you use legacy VRPN, you need to make sure proper routes are present in case of link failure.

Best,
Andy

View solution in original post

0 Kudos
8 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Enhanced Link selection with R82 might be an option for you:

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/T...

CCSM R77/R80/ELITE
Saranya_0305
Collaborator

Dear Mates,

I have created Mesh topology successfully in lab.

I have seen in document that VPN Interoperability not supported for Quantum Spark Appliance.

Can I configure VPN redundancy with star topology between a Quantum Enterprise Appliance and a Quantum Spark Appliance, with the Quantum Enterprise acting as the central gateway, when both are managed by the same Management Server?

or 

If Quantum Spark Appliance is not supported for VPN redundancy is there any other way?

 

Thank you for guidance.

 

Regards,

Saranya 

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Yes, more advanced topologies may required SD-WAN.

R82.00.10 may also bring some relevant improvements for Spark.

CCSM R77/R80/ELITE
0 Kudos
Saranya_0305
Collaborator

For VPN redundancy in Quantum Spark which are R81.10.XX firmware we need to configure SD-WAN.

For Quantum Enterprise Appliance static/dynamic routing protocol will work.

Is my understanding correct? Please correct if I am mistaken in my understanding.

 

Regards

Saranya

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Not exactly, configuring static / dynamic routing has little to do with the choice of ISP used as the source (peer).

Case in point Spark appliances support route based VPNs (VTI) or MEP just fine to my knowledge.

SD-WAN is just an option, a good one (but requires a license).

CCSM R77/R80/ELITE
0 Kudos
AmirArama
Employee
Employee

in order to have SD-WAN overlay between two VPN peers, both sides have to be enabled with Quantum SD-WAN and managed from the same MGMT/MDS.

for no interruption at all, Quantum SD-WAN is the way to go.

you can use either Domain or Route based VPN based on your needs. VPN Redundancy over multiple ISPs will work regardless by the SD-WAN.

the_rock
MVP Platinum
MVP Platinum

I would agree with that.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Apart from what Chris said, if you use legacy VRPN, you need to make sure proper routes are present in case of link failure.

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events