Is it possible to deliver VPN Site2Site with redundancy in VSX deployment using Maestro?
Old Firewall (CP 4800) used to connect Site2Site VPN to 3rd Party (CP 2200) with ISP Redundancy (2 ISP's), so that VPN Site2Site have redundancy (automatically failover if 1 ISP is down).
CP 4800 will be replaced with Maestro with VSX deployment, sk79700 says VSX doesn’t support ISP Redundancy.
I saw a thread that says the alternative way to give Redundancy in VPN Site2Site is using PBR Multi Hop and it’s available from R80.30 onwards.
Since Maestro OS is R80.20 SP, I haven’t found SK that declares R80.20SP Supports PBR Multihop, I only found that PBR can be setup in VSX Maestro sk137232.
or is there another alternative solution to give Redundancy on VPN Site2Site using VSX?
sk79700 (VSX doesn't support ISP Redundancy):
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Alternative Solution:
https://community.checkpoint.com/t5/General-Topics/PBR-With-Multiple-Tracking/td-p/14462
sk137232 (How to setup PBR in VSX on High Scalable Device)
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
#VSX #Maestro #VPN