Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
barisben
Explorer

IPsec Gateway is Always Defined Cluster Management IP

Hey, I'm trying to IPsec between sites in my lab to test CheckPointFW. I have management network 10.1.91.0/24 and managing CPs from this network. I defined cluster IP from this subnet and FWs have 2 WAN IP and the other site have also. When I check logs from the other site, it says phase1 trying to negotiate from the 10.1.91.27 (so cluster IP). But I want to specify it and tried somethings but nothing works.

1.jpg

When I select Always use this IP address->Selected address from topology table->WAN1, its negotiating.

2.jpg

I defined for both interoperable devices WAN IP but doesn't work.

3.jpg4.jpg5.jpg6.jpg

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

If you're using multiple WAN interfaces with VPN, you'll need to configure Link Selection as part of ISP Redundancy: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content... 

In R82, the Link Selection options are greatly improved: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/T... 

0 Kudos
the_rock
Legend
Legend

I took this screenshot from customers environment where this works 100%, no issues. Dont know if it matters, but their SECONDARY link IP is first in the list I pointed out.

Andy

 

Screenshot_1.png

 Btw, make sure option to apply vpn settings is checked at the bottom of the tab for isp redundancy.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events