Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
H4ppyM3
Contributor
Jump to solution

CP s2s vpn to Azure VPN Gateway (Active-Active)

Hi ALL,

 

Did someone build a VPN between on-prem Checkpoint ClusterXL ( act-stb ) and Azure VPN Gateway ( act-act ) ? If so, which type – route or policy based ? As referring https://support.checkpoint.com/results/sk/sk101275 preferred way is policy-based.

 

If Azure is act-act it will have 2 different public IP’s. How to build the encryption domain if the network behind azure is same for both remote-peers. ( NAT ? )

0 Kudos
1 Solution

Accepted Solutions
Alex-
Leader Leader
Leader

In this setup it is probably preferable to go for two route-based VPN with BGP.

sk176249 discusses this for Azure VWAN and CloudGuard instances, but the Azure VPN Gateway follows mostly the same pattern.

We have successfully configured two redundant VPN gateways to Azure with BGP using this approach.

View solution in original post

2 Replies
Alex-
Leader Leader
Leader

In this setup it is probably preferable to go for two route-based VPN with BGP.

sk176249 discusses this for Azure VWAN and CloudGuard instances, but the Azure VPN Gateway follows mostly the same pattern.

We have successfully configured two redundant VPN gateways to Azure with BGP using this approach.

H4ppyM3
Contributor

this sounds like a very good option. 

 

Thank you !!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events