- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
That's Serious Stuff!
To me, based on what you attached, seems like it would make sense to set one meshed community and have all 3 gateways included (2 Cisco sites would be presented as interoperable objects). That way, if say one Cisco side goes down, tunnel would still work to the other one.
Andy
Hello,
Thank you for your reply, is there any SK on how to configure this?
it's impossible to have the same encryption domain to 2 different interoperable objects
Sure you can.
Btw, I would do what @Martijn suggested, makes total sense. Also, you can set enc domains as empty group for everything (Cisco and CP), but make sure traffic is controlled with the correct rule, ie include whatever subnets need to participate.
Andy
Hi,
Consider using tunnel interfaces (VTI's) and a routing protocol (OSPF).
If a VTI goes down, OSPF will use the other VTI to route traffic.
Regards,
Martijn
Hi, thank you for your reply, i only manage the checkpoint cluster, ospf neeed to be configured on cisco ASA(managed by partner) as well?
Hi,
Yes, OSPF needs to be configured on both end of the VPN tunnel.
Regards,
Martijn
Hello,
routing with VTI is difficult to implement, our partner is not too technical, i found in a threat that it's possible, 1 community ,2 interoperable GW, same encryption domain,
2 VPN's Same Remote Encryption Domain - Check Point CheckMates
Its actually pretty simply. But, I mean, like anything in life, things are easy when you know it : - ). Anyway, check out link I posted while back about doing this for Azure vpn tunnel, hope it helps.
Andy
The solution is to use explicit MEP (Multiple Entry Point) feature inside VPN Community settings.
Site1 and Site2 will use the same VPN encryption domain. Inside MEP settings, Site1 can be set as Primary gateway and in case Site1 is not responding, VPN will switch to use Site2.
There is also option to use implicit MEP where you can choose which gateway should be used as primary and which as backup.
You got it! @Ayoub_Bou , implicit MEP option would be used if vpn domains overlap.
Andy
Hi,
Just swap Center gateways with Satellite Gateways each other.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Tue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Thu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY