- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello mates!
I got a situation!
Cenario:
I have one vpn tunnel site2site configure and operational. I need to configure a redundant (second) vpn tunnel with exactly the same configuration except for the source and destination peer address. The problem is, every time the firewall try to establish the connection, it chooses always the first WAN interface as the source even if the source ip address selection is set to "Automatically chosen according to outgoing interface". I only have one default route configured for the primary link.
What should i accomplish to resolve this problem?!
Hardware in use: Checkpoint Quantum Spark 1590
Thanks in advance!
I was explaining how the feature works.
Unfortunately, it cannot be used to achieve your goal which, as I understand it, is to create TWO connections to the same encryption domain using different source/destination IPs for both tunnels.
This requires the use of MEP (Multiple Entry Point), among other things which are not currently supported on locally managed Quantum Spark appliances.
ISP Redundancy can be used to use different WAN IPs for a given VPN endpoint (requires multiple Internet connections).
I assume its locally managed smb with 2 wan links?
Andy
Hi The Rock
Yes it is!
Can you send screenshots of how its configured, if possible? Just blur out sensitive data.
Andy
Not clear - does it mean even if the first ISP is down, it will not use the second WAN ? What about probing settings?
Hi G_W
First: I want to know if it is possible to establish both tunnel up and running according to the cenario i presented.
Secord: If the first condition is possible, how to solve it. Is it necessary to add a new default route for the second link?!
That's what Automatically Chosen According to Outgoing Interface will do: use the IP address associated with the interface that is used for the "next hop" to reach that address.
Unless you have a specific route configured for the remote encryption domain, the IP associate with your Default Route (i.e. via WAN1) will be used.
Or you configure ISP Redundancy.
Hi PhoneBoy
You're saying that to make both tunnel up and operational i have to configure 2 specific static route instead of depending on the Default route?! 'Cause i already have a specific static route for the second link, but even so, isn't working!
Sounds like that to me.
Andy
I was explaining how the feature works.
Unfortunately, it cannot be used to achieve your goal which, as I understand it, is to create TWO connections to the same encryption domain using different source/destination IPs for both tunnels.
This requires the use of MEP (Multiple Entry Point), among other things which are not currently supported on locally managed Quantum Spark appliances.
ISP Redundancy can be used to use different WAN IPs for a given VPN endpoint (requires multiple Internet connections).
Is the remote peer IP also different? The ip you use to setup the tunnel with?
Otherwise you have overlap and it will not work.
Hi Lesley
Yes. the remote peer is also different on both tunnels.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
1 | |
1 | |
1 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY