- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- VPN S2S 2 ISPs + AWS
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN S2S 2 ISPs + AWS
Hello,
We have a cluster on R81.10, in which we have two links/ISP from different suppliers. We would like to enable redundancy for a VPN with AWS.
EX:
ISP 1
ISP2
In other words, having 2 active tunnels, when the ISP1 tunnel fails, the ISP2 tunnel is activated.
As we know that S2S VPNs with AWS are route based, we have already ruled out using link selection.
In a first conversation with AWS, they informed us that it will have to be done via BGP.
Has anyone already implemented this configuration?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why not use MEP? It applies if you have more than 1 center gateway, unless you are strictly referring to ISP redundancy?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, The_Rock,
Tks for feedback.
What I need is ISP redundancy to have redundancy between two tunnels.
Tks
Cristian Rosa
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey mate,
Not so sure thats possible, because if you think about it logically, how would the AWS side ever know that there was ISP like change and would be aware of new external IP?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Andy,
This scenario is common, how would I do VPN redundancy using VTI/AWS?
Is there no possibility?
Tks
Cristian Rosa
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you tried this? https://support.checkpoint.com/results/sk/sk108958
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello, PhoneBoy
Tks for feedback.
What I need is ISP redundancy to have redundancy between two tunnels.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From sk108958: "To detect when a tunnel goes down and to route traffic through the second tunnel, we use BGP."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
But in this case, the reference is to the second tunnel on the AWS side. In AWS there will be redundancy, but on the Checkpoint side.
Note that there is only one peer/ISP on the Checkpoint side.
Tks
Cristian Rosa
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We had a client who wanted similar thing and we did end up using BGP, though this was Azure, but literally the same concept.
