Hi all,
I have a question about IPSec VPN in combination with Remote Access VPN (IPSec).
Please consider the below topology. It consists of three Check Point clusters (1, 2, and 3) at three separate locations. All clusters have their own connection to the Internet. Between clusters 1 and 2 a backbone network exists (routing traffic between Net1 and Net2). There is a site-2-site IPSec VPN between cluster 3 and 1 and between cluster 3 and 2 (both not shown in the drawing). The VPN domains of clusters 1, 2, and 3 contain Net1, Net2, and Net3 respectively. This works like a charm.
+---------+
| |
ISP1 ---+ cluster +------- Net1
| 1 |
| +---+
+---------+ |
|
+---------+ |
| cluster | |
Net3 ---+ 3 +--- ISP3 I N T E R N E T | backbone
| | |
+---------+ |
|
+---------+ |
| +---+
| cluster |
ISP2 ---+ 2 +------- Net2
| |
+---------+
Now the question. Is it possible to configure a RemoteAccess VPN where users connect to cluster 1 and have access to Net1 (easy), but also to Net2 (routed over the backbone) and Net3 (using the site-2-site VPN between clusters 3 and 1)?
And, as a bonus challenge, can we configure a backup RemoteAccess VPN (manual selection by users, no MEP) that will allow remote users to connect to cluster 3 and have access to Net1, Net2, and Net3 as well?
Thanks in advance!
Regards,
-Frank