- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
Anyone known how configure a VPN IPSEC over MPLS?
Actually i have a tunel established using my ISP between two Check Point Gateway, now i have a MPLS link and i want to encrypt this traffic.
Devices:
1 Manager for Corporate and Branch Site;
1 Corporate Gateway;
1 Branch site Gateway.
My doubt is, i have some others tunnels using my ISP on Corporate gateway, if i change the link selector to use MPLS, how the VPN´s configured today understand this?
Best Regards
Lucas
Hi all,
The final solutions was:
Uncheck "Apply settings to VPN Traffic" from the ISP Redundancy settings.
Configure the Link Selection to probe my two ISP´s and the MPLS and set the primary address to MPLS.
Renew the certificates from Gateway 01 and Gateway 02 adding all ip address of ipsec as SAN.
Regards
Lucas
Is the MPLS link on the same interface or a different interface from your ISP?
Assuming different, then I think if you use "Calculate IP Based on Network Topology" it should use the IP facing that network.
Hi Dameon,
Thank you!
Yes, is a different interface.
I have ISP Redundancy configured also, with "Apply settings to VPN Traffic" because i have VPN established with anothers peers over internet and for redundancy of internet and the ipsec vpn with this peers.
Also, if i uncheck "Apply settings to VPN Traffic" and use "Calculate IP Based on Network Topology", Can i have a problem with link failover or with others tunnels?
Lucas
Depends on if the remote end of the MPLS VPN is Check Point or not.
Hi Dameon,
Thank you for all your support.
Yes, is a check point.
Do you know what happens when I uncheck the option "Apply settings to VPN Traffic" from ISP redundancy settings?
I will lose the failover with others peers?
Regards
Lucas
I don't think you need to disable "Apply settings to VPN Traffic" in this case (but maybe I'm wrong here).
Hi Dameon,
If i do not disable the option "Apply settings to VPN Traffic", I am not be able to change the link selection on the IPSec VPN tab. ![]()
Regards
Lucas
It should be ok.
It's similar to the following scenario in the documentation, which requires a couple extra steps to be done: Link Selection
Hi Dameon,
Thank you so much.
I will try, I will be back with results.
Regards
Lucas
Hi all,
The final solutions was:
Uncheck "Apply settings to VPN Traffic" from the ISP Redundancy settings.
Configure the Link Selection to probe my two ISP´s and the MPLS and set the primary address to MPLS.
Renew the certificates from Gateway 01 and Gateway 02 adding all ip address of ipsec as SAN.
Regards
Lucas
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY