Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gm446
Contributor

VPN Tunnel between ClusterXL and AWS

Hi everyone,

I have a basic question about establishing Site to Site between Checkpoint cluster and AWS VPC.


Until now, the deployment was a single gateway and i have two tunnels with numbered VTI according to AWS guide. We've recently switched to ClusterXL deployment, and I'm unsure about how to adjust the tunnel configurations to ensure functionality after a fail over.

Should i remove one VTI from the primary and set it on the secondary? should i configure both VTIs in both gateways with other IP addresses and make the VTI address the VIP?

i will appreciate any help with this subject.

Thank you in advance,
Yossi.

0 Kudos
2 Replies
emmap
Employee
Employee

You should configure both VTIs on both cluster members, with tunnel IP per member and a VIP. Details are in the VPN admin guide.

gm446
Contributor

Thank you!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events