- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Guys,
I have a requirement where i need to create two route-based ipsec tunnels between Checkpoint & third party vendor & there are around 500 clients to which i need to create tunnels in active/backup manner.
Kindly suggest how to achieve this.
Hello!
First of all, you'd have to use route-based VPN as you said, instead of a pure policy-based VPN.
So what you do is define two VTI interfaces on the gateway, acting as the logical interfaces for the VPN, and then set up routing based off that, where you also set up which third party gateway it will communicate towards.
If you want to use static routes with IP tracking, or dynamic protocols such as OSPF or BGP is up to you, I would personally recommend dynamic protocol.
See this guide when it comes to the VTIs etc:
https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VP...
As for the VPN itself, you create a policy based VPN as usual, but leave the VPN domains as empty groups, (since the routing will decide what will traverse over the tunnel).
Thanks for your suggestions but here my question is, Is it possible to keep two VPN tunnel active on different ISP ?
As i know we can only select single interface in link selection option of IPsec VPN.
I mean, you could technically route your interoperable device IPs out on different ISPs with definitive /32 routes to their public IPs.
Should be possible.
Then you'd just use the routing in the VTI tunneling to decide which tunnel to use etc.
It means link selection does not matter if we use route based VPN to select the outgoing tunnel ? Am i correct ?
From checkpoint end nope it is not possible since you can terminate tunnel only on one ISP. While you can create two tunnels with two ISP for remote end.
that is what i was trying to tell. Only one tunnel will be UP at a time right ?? Do we need to use ISP redundancy for auto tunnel failover.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY