- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: R80.40 S2S VPN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.40 S2S VPN
I am looking to set up a S2S VPN with a customer. While exploring for options i came across 2 types of modes i.e. Star and Mesh. Which one should be selected if VPN is to be stablished with 1 customer only.. or any of them works fine in this case.
Also, once the tunnels are stablished how can i verify if the configuration is fine and tunnels are stablished. I had done this in ASA and there was a section where tunnels are visible in ASDM but couldn't find something similar for Checkpoint.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For all regular VPNs you would likely use the Star Communities. Mesh is only necessary if you want to connect multiple Sites with you and also between them. It's a mesh like the name says 🙂
For monitoring you can ever use the old SmartView Monitor "Tunnel & User Monitoring" under Logs --> new Tab and at the bottom under "external apps".
On the Gateways you can see it even better with this command (Expert): vpn tu tlist -p PEER_IP
You can see all SA with the established subnets etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For all regular VPNs you would likely use the Star Communities. Mesh is only necessary if you want to connect multiple Sites with you and also between them. It's a mesh like the name says 🙂
For monitoring you can ever use the old SmartView Monitor "Tunnel & User Monitoring" under Logs --> new Tab and at the bottom under "external apps".
On the Gateways you can see it even better with this command (Expert): vpn tu tlist -p PEER_IP
You can see all SA with the established subnets etc.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can also use "vpn tu" from the command line of one of the Gateways. Select option 3 and put in the specific IP of the peer to verify the status of the tunnel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Excellent response!!
Andy
