- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone!
I hope you can help me with a question I have for a project with a customer.
I would like to know how I could generate a DNS redundancy when I have the following scenario:
-When FW1 is down and inactive for some reason.
-Subsequently, we will modify the DNS name vpn.company.com so that it now points to the public IP of FW2
-However, we want to know if there is any configuration so that we do not have to reconfigure anything in the Remote Access VPN Client so that it can now resolve to the same vpn.company.com domain but now pointing to FW2
In other words:
-Remote Access VPN client I configure it only once with vpn.company.com
-And after making the necessary configurations in Check Point for this DNS redundancy.
-And there is an event where FW1 goes down and FW2 is now the primary.
-That VPN client, just by pointing to the vpn.company.com domain, is directed to FW2 without reconfiguring anything (without needing to recreate the VPN site).
is this possible?
Doing some research, I think the configuration we need is the following in the file $FWDIR/conf/trac_client_1.ttm
Is the information correct?
Do I need to configure anything else?
I hope you can help me.
Greetings!
Hey @israelsc
Im fairly positive this is the sk you need to follow. My colleague and I did this for a customer back in 2021 and works fine.
Andy
https://support.checkpoint.com/results/sk/sk103440
Also, not 100% certain if below is also required, though I believe we also did this one:
https://support.checkpoint.com/results/sk/sk131612
Hey @israelsc
Im fairly positive this is the sk you need to follow. My colleague and I did this for a customer back in 2021 and works fine.
Andy
https://support.checkpoint.com/results/sk/sk103440
Also, not 100% certain if below is also required, though I believe we also did this one:
https://support.checkpoint.com/results/sk/sk131612
Thank you very much @the_rock
I have set this https://support.checkpoint.com/results/sk/sk103440 and tested on 2 different PCs, both automatically resolve the DNS as I change the A record in the DNS service.
In case for someone who is also testing this and VPN Endpoints not take change automatically, I leave a solution that TAC shared with us in a SR:
In theory, the VPN client should be able to automatically update to the new IP address without the need to delete and recreate the profile. However, there are several factors that can affect this behavior:
To ensure that the VPN client automatically updates to the new IP address without user intervention, you can configure the client to resolve the DNS name at every connection. Here are the steps to achieve this:
Based on https://support.checkpoint.com/results/sk/sk167254
Great job! Glad we can help.
Have a nice weekend.
Andy
@israelsc you want to have a redundant entry via remote access to your network. MultipleEntryPoint MEP is the feature you need. The client knows all entry points and can probe all of them. You can configure to have load balancing or active/backup for the connections from your remote clients.
100% valid...I implemented that for a client couple of years back.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY