- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
I would like set up vpn via an interface (not external we use for others vpn) to vpn community where i have an interoperability device.
How do i send the traffic go out on that interface (all the parameter are for locally managed)? the peer is direct attached on that interface so he know the route to the peer but traffic seems not going to that path. Even other peer on that interface we would like setup vpns and gateway has the route to the peer.
Thank you
If you attach simple diagram, it would help us guide you.
If you want to terminate VPNs on different interfaces, you need to adjust the Link Selection settings on the gateway object to determine the IP based on the routing table.
Yes but then vpn on external interface won't work anymore
It should if you’ve configured it correctly (both Link Selection and the routing)
In any case, a network diagram would be exceptionally helpful.
You mean if set link selection on interface towards internal net when terminate my vpn for intranet the vpn using external interface main address facing internet still still work? I have already VPN facing internet interface .5 and would like to set up vpns to my interoperability device via interface 192.168.1.1. static route to 192.168.2.1 is set.
You set the link selection to be based on routing (instead of a fixed value or interface).
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Top...
sorry what do you mean exactly? can you share a screenshot?
From the doc @PhoneBoy gave you. By the way, if you look in demo dashboard, you can see same settings.
Andy
You configure the settings in SmartConsole
From the left navigation panel, click Gateways & Servers.
Double-click the Security Gateway object.
Click IPsec VPN > Link Selection.
Remote peers can connect to the local Security Gateway with one of these settings:
Always use this IP Address
Calculate IP based on network topology
Using DNS resolving
Using probing - Link redundancy mode
Yes is what I did and choose:
Calculate IP based on network topology
But this parameters is not for locally managed?
Assuming you mean a locally managed SMB appliance, there is a similar setting there:
I mean the parameters you told me to set is related to: Remote peers can connect to the local Security. But I need traffic from central gateway to intranet peers go through that interface
I assuming that you cannot use 2 interface for 2 vpn with interoperability device. I had a same issue a long time ago and CP cannot use 2 vpn interfaces with 3rd party gateways. I am not sure the latest gaia can fully support DPD.
If the remote peers are CheckPoint you can accomplish to use multiple interface for vpn that "Calculate IP based on network topology" options.
I would suggest you contact with TAC and get some enquiry.
so if set link selection that interface to intranet, internet vpn wont work right?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
7 | |
6 | |
5 | |
4 | |
4 | |
4 | |
3 | |
3 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY