Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dido-Master
Participant
Participant

VPN Site2Site

Hello mates!

 

I got a situation!

 

Cenario:

I have one vpn tunnel site2site configure and operational. I need to configure a redundant (second) vpn tunnel with exactly the same configuration except for the source and destination peer address. The problem is, every time the firewall try to establish the connection, it chooses always the first WAN interface as the source even if the source ip address selection is set to  "Automatically chosen according to outgoing interface". I only have one default route configured for the primary link.

 

What should i accomplish to resolve this problem?!

Hardware in use: Checkpoint Quantum Spark 1590

Thanks in advance!

0 Kudos
10 Replies
the_rock
Legend
Legend

I assume its locally managed smb with 2 wan links?

Andy

0 Kudos
Dido-Master
Participant
Participant

Hi The Rock

 

Yes it is!

0 Kudos
the_rock
Legend
Legend

Can you send screenshots of how its configured, if possible? Just blur out sensitive data.

Andy

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Not clear - does it mean even if the first ISP is down, it will not use the second WAN ? What about probing settings?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Dido-Master
Participant
Participant

Hi G_W

 

First: I want to know if it is possible to establish both tunnel up and running according to the cenario i presented.

Secord: If the first condition is possible, how to solve it. Is it necessary to add a new default route for the second link?!

0 Kudos
PhoneBoy
Admin
Admin

That's what Automatically Chosen According to Outgoing Interface will do: use the IP address associated with the interface that is used for the "next hop" to reach that address.
Unless you have a specific route configured for the remote encryption domain, the IP associate with your Default Route (i.e. via WAN1) will be used.
Or you configure ISP Redundancy. 

0 Kudos
Dido-Master
Participant
Participant

Hi PhoneBoy

You're saying that to make both tunnel up and operational i have to configure 2 specific static route instead of depending on the Default route?! 'Cause i already have a specific static route for the second link, but even so, isn't working!

0 Kudos
the_rock
Legend
Legend

Sounds like that to me.

Andy

0 Kudos
PhoneBoy
Admin
Admin

I was explaining how the feature works.
Unfortunately, it cannot be used to achieve your goal which, as I understand it, is to create TWO connections to the same encryption domain using different source/destination IPs for both tunnels.

This requires the use of MEP (Multiple Entry Point), among other things which are not currently supported on locally managed Quantum Spark appliances.
ISP Redundancy can be used to use different WAN IPs for a given VPN endpoint (requires multiple Internet connections).

0 Kudos
Lesley
Mentor Mentor
Mentor

Is the remote peer IP also different? The ip you use to setup the tunnel with?

Otherwise you have overlap and it will not work. 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events