- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- VPN Community with a remote device that has ISP re...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Community with a remote device that has ISP redundancy
Hello everybody
Right now having a Check-point Open server running R81.20 with a VPN community connecting to a Checkpoint 1570 device which has 2 ip addresses.
so Local gateway has 1 ip
remote gateway has 2
if primary connection drops out on remote gateway the Site-to-site connection drops because there is no automatic ISP redundancy on the VPN site. right now i have to manually remove the device from the VPN Community and add the device again but with the secondary ip address to fix this. and bring up the tunnel again.
I have created 2 Interoperable device for this. 1 with Primary ip address. and 1 with secondary ip address.
there must be a way to avoid this, can anybody shed some light over this. Looking in the support articles doesnt seem to clear about how i can achieve this
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can probably do something similar to the following: https://support.checkpoint.com/results/sk/sk174848
The part that is most relevant to your situation is how the VPN community is configured (both "interoperable devices" part of the encryption domain and enabling/configuring MEP in the community).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can probably do something similar to the following: https://support.checkpoint.com/results/sk/sk174848
The part that is most relevant to your situation is how the VPN community is configured (both "interoperable devices" part of the encryption domain and enabling/configuring MEP in the community).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I once got ask super valid question by the cusotmer..."Andy, whats even the point of ISP redundancy for S2S vpn tunnels, when there wont be automatic failover to 2nd link if primary fails and you have to do everything manually?"
I could not give them a good answer, because its totally LOGICAL question.
I think sk Phoneboy gave you is your best option.
Andy
