Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SdanteMate
Contributor

Checkpoint cluster Site-ti-Site VPN - PaloAlto (Dual ISP) Fails Over

Dear mates,

 

I have a scenario, a PaloAlot having two ISP and we want to configure two VPN links to Checkpoint cluster single ISP.

From Palo Alto, there is a tunnel IF with a private IP that you can use for failover monitoring, but on the Checkpoint end, the packet comes and decrypted with action drop since the IP is also part of the internal range. 

On checkpoint, I set up a single VPN community (STAR), with checkpoint as the center and two PaloAlto objects satellite (same domain subnet).

 

Is there any guide regarding this case? 

Cheers

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

This requires MEP.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events