- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
I would like set up vpn via an interface (not external we use for others vpn) to vpn community where i have an interoperability device.
How do i send the traffic go out on that interface (all the parameter are for locally managed)? the peer is direct attached on that interface so he know the route to the peer but traffic seems not going to that path. Even other peer on that interface we would like setup vpns and gateway has the route to the peer.
Thank you
If you attach simple diagram, it would help us guide you.
If you want to terminate VPNs on different interfaces, you need to adjust the Link Selection settings on the gateway object to determine the IP based on the routing table.
Yes but then vpn on external interface won't work anymore
It should if you’ve configured it correctly (both Link Selection and the routing)
In any case, a network diagram would be exceptionally helpful.
You mean if set link selection on interface towards internal net when terminate my vpn for intranet the vpn using external interface main address facing internet still still work? I have already VPN facing internet interface .5 and would like to set up vpns to my interoperability device via interface 192.168.1.1. static route to 192.168.2.1 is set.
You set the link selection to be based on routing (instead of a fixed value or interface).
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Top...
sorry what do you mean exactly? can you share a screenshot?
From the doc @PhoneBoy gave you. By the way, if you look in demo dashboard, you can see same settings.
Andy
You configure the settings in SmartConsole
From the left navigation panel, click Gateways & Servers.
Double-click the Security Gateway object.
Click IPsec VPN > Link Selection.
Remote peers can connect to the local Security Gateway with one of these settings:
Always use this IP Address
Calculate IP based on network topology
Using DNS resolving
Using probing - Link redundancy mode
Yes is what I did and choose:
Calculate IP based on network topology
But this parameters is not for locally managed?
Assuming you mean a locally managed SMB appliance, there is a similar setting there:
I mean the parameters you told me to set is related to: Remote peers can connect to the local Security. But I need traffic from central gateway to intranet peers go through that interface
I assuming that you cannot use 2 interface for 2 vpn with interoperability device. I had a same issue a long time ago and CP cannot use 2 vpn interfaces with 3rd party gateways. I am not sure the latest gaia can fully support DPD.
If the remote peers are CheckPoint you can accomplish to use multiple interface for vpn that "Calculate IP based on network topology" options.
I would suggest you contact with TAC and get some enquiry.
so if set link selection that interface to intranet, internet vpn wont work right?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
10 | |
7 | |
6 | |
6 | |
5 | |
5 | |
4 | |
4 | |
4 |
Mon 22 Sep 2025 @ 02:00 PM (EDT)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security AMERTue 23 Sep 2025 @ 06:00 PM (IDT)
Under the Hood: CloudGuard Network Security for Nutanix - Overview, Onboarding, and Best PracticesWed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Wed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY