Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ANARINE
Participant

How to specify secondary IP address in Checkpoint S2S vpn

I have 2 site to site VPNs from CP gateway to 2 Fortigates as shown below.

 

Fortigate_SiteB ---------  FortigateA/CPFW (vrrp) ------------Fortigate_SiteC

 

The FortigateA/CPFW are running VRRP on its 'external' interface.

The FortigateA/CPFW is behind a NAT device with port forwarding enabled and working toward the VRRP ip.

 

The VPNs do connect successfully. But when CPFW is the active firewall, Site C gets intermittent timeouts every other minute. (observed when I  do continuous ping) . It seems to be reconnecting every so often.

 

On the FortigateA I have set the LocalID to the secondary ip (vrrp address). Is there a similar setting in CheckpointFW ?

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I assume you’d have to set up MEP to support the Remote VPN Peer having more than one IP.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events