I have 2 site to site VPNs from CP gateway to 2 Fortigates as shown below.
Fortigate_SiteB --------- FortigateA/CPFW (vrrp) ------------Fortigate_SiteC
The FortigateA/CPFW are running VRRP on its 'external' interface.
The FortigateA/CPFW is behind a NAT device with port forwarding enabled and working toward the VRRP ip.
The VPNs do connect successfully. But when CPFW is the active firewall, Site C gets intermittent timeouts every other minute. (observed when I do continuous ping) . It seems to be reconnecting every so often.
On the FortigateA I have set the LocalID to the secondary ip (vrrp address). Is there a similar setting in CheckpointFW ?