Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
hdas
Participant

ClusterXL - VxLAN over redundant IPSec VPN (R81.10 and future release)

Hello Mates,

does someone know if the R81.10 will support redundant IPSec VPN and VxLAN over IPSec?

As far as I know, the R80.40 and R81 do not support multiple link selection for the multiple VPN tunnels (different public subnets).

This is what I want to achieve:

VxLAN_IPSec.jpg

 

Thanks,

6 Replies
Benedikt_Weissl
Advisor

You could try VPN Link Selection in Load Sharing mode. According to the FAQ here (https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...) it will only create one VPN Tunnel and balance the packets between the different links.

0 Kudos
hdas
Participant

My goal was to find a way to use both internet connections at the same time.

0 Kudos
Benedikt_Weissl
Advisor

You can use ISP Redundancy for LAN to WAN Traffic und VPN Load Sharing (https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_SitetoSiteVPN_AdminGuide/htm...) for Site2Site VPN Traffic

0 Kudos
PhoneBoy
Admin
Admin

Pretty sure this is not among the features supported, see: https://community.checkpoint.com/t5/Product-Announcements/R81-10-EA-Program-Production/ba-p/110053

Mostly likely this exact configuration is an RFE and I encourage you to bring it through your local Check Point office.

hdas
Participant

Hi PhoneBoy,

I don't know if the local office will be able to support me on this. We need to look elsewhere, disaggregation maybe? Just think how useful would be to have the control plane (VRF, virtual router..etc) in ClusterXL? 😍

0 Kudos
genisis__
Advisor

not sure about this, but could you not just run x2 GRE tunnels through the Checkpoints? 

0 Kudos