Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
arcotangente
Participant

VPN Tunnel failover with 2 ISP's and Juniper gateway on remote side

Hi guys, 

My scenario is as follows: on the main site we've got a Checkpoint cluster running R80.10 and a single ISP, that runs an IPSEC VPN tunnel to our secondary site, where we have a Juniper SRX firewall.

Recently a second ISP line has been added to the secondary site to improve the availability and the target is to setup an automatic mechanism on both sides that in case the tunnel through the ISP1 goes down, the IPSEC tunnel will automatically raised on ISP2. 

What's the best way to do this? a single VPN community with both satellite gateways (ISP1 and ISP2)? What else, should I enable DPD on both gateways (Checkpoint and Juniper)?

 

Thanks in advance!

0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events