Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mlinzer
Explorer

Site to Site VPN load balancing across dual links

Hi everyone,

I have a VPN tunnel connecting 2 sites, where all traffic is routed over the tunnel. I just installed dual 100Mb links between the sites, which I would like to use as Active/Active. The service provider installed dual switches on each end, and combines the 2 links using LACP between the switches. I connect the firewalls with a single port to one switch at each site.

My concern is that since all traffic goes over a single VPN tunnel, the LACP will not load balance the traffic between the 2 lines, but will treat it all as one "session". How can I get the traffic to run over both links (and achieve aggregate throughput of 200Mb)?

My other idea was to connect 2 ports on each firewall, one to each line, and bond them together into a single interface, then let the Checkpoint handle the load balancing (using which mode settings?). Which method would work better?

See network diagram below:

 

0 Kudos
1 Reply
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events