- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I ask here because the documentation is very confusing about thesetopics, maybe you can help me to pick the right option.
A customer has a cluster with a s2s vpn tunnel, it is configured like a domain vpn, using a public ip conected to a ISP1.
Now he needs to add 2 new tunnels, but using 2 new ISP, each one providing his own public ip to be configured in the gateway.
Which type of vpn scenario would be the right one? (still in this community with link selection, new route based vpns, vti.....)
The 3 remote third party gateways are not Check Point devices.
Thanks in advance!
The only way this can work right now is for each VPN link to route out a different physical interface with the relevant IP address assigned.
This requires Link Selection to be set up accordingly.
Otherwise, it is not possible to use a different IP for a different VPN peer.
Also, if you're mixing route and domain-based VPNs on the same gateway, see: https://support.checkpoint.com/results/sk/sk109340
Hopefully, with the changes planned for R82, this sort of scenario should be easier to support,.
The only way this can work right now is for each VPN link to route out a different physical interface with the relevant IP address assigned.
This requires Link Selection to be set up accordingly.
Otherwise, it is not possible to use a different IP for a different VPN peer.
Also, if you're mixing route and domain-based VPNs on the same gateway, see: https://support.checkpoint.com/results/sk/sk109340
Hopefully, with the changes planned for R82, this sort of scenario should be easier to support,.
So if I understand it, the way to do this keeping the vpn1 with isp1 as domain vpn is to configure the other 2 as routed vpn, using link selection for this gateway as calculate ip based on network topology and 2 static routes for the two remote networks, each one reachable behing vpn tunnel 2 and vpn tunnel 3, right?
That sounds about right, yes.
Its right in theory, but in reality, different story... : - (
Lol... What do you mean? Did you have problems with this configuration?
I dont have problems with it, but its not so easy to make it work, at least from my experience.
Ok, understood. Thanks.
Look my answer and my contributes here https://community.checkpoint.com/t5/Management/Link-selection-into-a-VPN-Community-Settings-R81-20/m...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 18 | |
| 12 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY