- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I need your help. I have this scenarious:
Site1: Managment server with cluster( 2x gateways, and 2 ISP ( A.A.A.A + B.B.B.B)
Site2: Managment server with cluster( 2x gateways, and 2 ISP ( C.C.C.C + D.D.D.D)
My questions is: When i make site-to-site VPN with site 1 and 2, i need garanted redundancy of ISP. What is a best pratices for this scenarious?
Thanks
Please read the documentation, I believe it covers what you need. If not, let me know.
Hi _Val_
Thanks for your reply.
Yes, already read this documentation. Maybe my first post not is a very complete.
When i create a site-to-site vpn i need create interoperable device (one for a ISP) and put it all in VPN Communitie, because i have two managments servers
Thanks
Keep in mind, its NOT supported to use same interoperable object in more than 1 vpn community. As a a matter of fact, if you do that, policy install will fail, 100%. The only way it would work is if you clone existing int. object, give it another name, but then there is no way to differ which community will take presedence and probably only 1 tunnel may show as up, you would not even see the other ones.
Best,
Andy
Why Interoperable? Do Externally Managed GWs. What's the issue, then?
Hi,
This is scenarios:
I need to create a site-to-site VPN to connect sites 1 and 2. One requirement is: if ISP A.A.A.A has a problem, I need ISP B.B.B.B to maintain a VPN connection.
My question is: When I create a VPN community for connecting site 1 to site 2, as this site has a different management server, how can I tell the Sattelite Gateways that I have 2 possible ISP connections? I need to create 2 written interoperable devices right?
How do you suggest?
See...key here is that even with ISPR configured, other side needs to be aware of say site's 1 both links (same the other way around) and since its NOT supported to have same interoperable object, or in your case externally managed gateways (as its CP) in the same community, personally, I would approach TAC with an official answer as far as best approach.
Maybe simple network diagram may also help us,
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY