- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- VPN Multiple interface interoperability device
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Multiple interface interoperability device
Hi
I would like set up vpn via an interface (not external we use for others vpn) to vpn community where i have an interoperability device.
How do i send the traffic go out on that interface (all the parameter are for locally managed)? the peer is direct attached on that interface so he know the route to the peer but traffic seems not going to that path. Even other peer on that interface we would like setup vpns and gateway has the route to the peer.
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you attach simple diagram, it would help us guide you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you want to terminate VPNs on different interfaces, you need to adjust the Link Selection settings on the gateway object to determine the IP based on the routing table.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes but then vpn on external interface won't work anymore
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It should if you’ve configured it correctly (both Link Selection and the routing)
In any case, a network diagram would be exceptionally helpful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You mean if set link selection on interface towards internal net when terminate my vpn for intranet the vpn using external interface main address facing internet still still work? I have already VPN facing internet interface .5 and would like to set up vpns to my interoperability device via interface 192.168.1.1. static route to 192.168.2.1 is set.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You set the link selection to be based on routing (instead of a fixed value or interface).
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Top...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sorry what do you mean exactly? can you share a screenshot?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From the doc @PhoneBoy gave you. By the way, if you look in demo dashboard, you can see same settings.
Andy
You configure the settings in SmartConsole
-
From the left navigation panel, click Gateways & Servers.
-
Double-click the Security Gateway object.
-
Click IPsec VPN > Link Selection.
Remote peers can connect to the local Security Gateway with one of these settings:
-
Always use this IP Address
-
Calculate IP based on network topology
-
Using DNS resolving
-
Using probing - Link redundancy mode
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes is what I did and choose:
Calculate IP based on network topology
But this parameters is not for locally managed?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Assuming you mean a locally managed SMB appliance, there is a similar setting there:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I mean the parameters you told me to set is related to: Remote peers can connect to the local Security. But I need traffic from central gateway to intranet peers go through that interface
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I assuming that you cannot use 2 interface for 2 vpn with interoperability device. I had a same issue a long time ago and CP cannot use 2 vpn interfaces with 3rd party gateways. I am not sure the latest gaia can fully support DPD.
If the remote peers are CheckPoint you can accomplish to use multiple interface for vpn that "Calculate IP based on network topology" options.
I would suggest you contact with TAC and get some enquiry.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
so if set link selection that interface to intranet, internet vpn wont work right?
