yes.. I have tested it in lab, failover is happening once the link monitor fails and traffic will switch over to secondary vpn within few seconds..
Link monitor concept generally used in other vendors for vpn redundancy between on-premise firewall and AWS/Azure using static routing.. I just tested it on checkpoint and its working..
I would like to know,
is vpn redundancy on checkpoint achievable only by keeping "Empty Group" on VPN domain, either its dynamic routing or static routing with link monitor?
OR
is vpn redundancy on checkpoint can also be achievable by keeping "Specific Network" on VPN domain without using MEP?
Because my customer needs vpn redundancy, but they are concerned about using "Empty Group" on vpn domain..