- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team,
I am planning to create a loopback interfaces on my HA cluster with same Public IP to terminate the IPsec VPN tunnels. It is required as I am having private IP address on external interface and I don't want to NAT the IP on Internet router.
Questions:
1. Is that setup feasible , Shall I give the same public IP on both the members as loopback interfaces are not a part of cluster.
2. How would I choose the loopback interface IP as an Peer IP under Gateway Cluster properties -> IPsec VPN -> Link Selection I don't see an option to set this IP to be used as VPN peer IP for my third parties.
3. How this loopback interface chooses physical interfaces to route its traffic
Regards
Anshu Bathla
1. Is that setup feasible , Shall I give the same public IP on both the members as loopback interfaces are not a part of cluster.
That's not possible for your needs. You have to create a dummy cluster-interface. The members are assigned private IPs and the VIP will be your public IP.
With these configuration you can choose your public IP in all the needed sections in VPN link selection.
Wolfgang
Thanks Wolfgang,
Shall I consider that as of now terminating the IPsec VPN is not at all possible on Loopback interfaces on Checkpoint Firewalls?
Just set the Link Selection IP to a static IP which does not have to be associated with a gateway interface at all.
Hi Anshu,
we also have the same requirement, Were u able to make it work with the dummy cluster interface. Please share your feedback
HI,
have you any feedback for this configuration? can we finalise the VPN IPSEC on a dummy INterface ?
What doesn't it mean exactly? should I define on GAIA System also an interface with the private IP address then define the public IP addresse on the CLuster Topologie?
Thank you for your reply
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY