Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
PankajTiwari1
Explorer

IPSEC failvoer not workign with MPLS link

Hello to all.

This is my first post here. I hope you can help me to address the investigation rightly.

 

SCENARIO

Main Site - Check Point R80.40

VPN Domain - 192.168.10.0/24

 

Remote site - Checkpoint R81.10

VPN Domain - 192.168,60.0/24

 

i am facing the issue with MPLS failover with IPSEC VPN.i have two link fist one is ILL( Internet Lease Line) and secondary is a MPLS link. i have to crate the redundancy with with my MPLS network whenever i crate the tunnel my all interface traffice will go through only IPSEC however it MPLS traffic or it is IPSEC traffic. please find the attached Network Diagram and suggest.

 

Untitled.png

0 Kudos
4 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

If you want control by routing metrics, VTI could be an option for you rather than domain based VPNs.

Refer also sk56384.

CCSM R77/R80/ELITE
0 Kudos
PankajTiwari1
Explorer

I try this SK but no luck.

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

As above please look into VTI route based VPNs.

It's covered in detail in the VPN Admin Guide.

CCSM R77/R80/ELITE
0 Kudos
PankajTiwari1
Explorer

Hello Chris,

 

thanks for your reply but it is a route based VPN i try with disabling VTI interface but after disabling VTI interface all traffic will forward through MPLS interface but the issue is i am facing high lattancy because it will crated a tunnel over the MPLS link according to SK it is a plan taxt link.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events