Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
khodgson_bts
Contributor
Jump to solution

VPN between on-premise cluster and Azure using VTI

Evening all. I'm hopeful that someone can help me with this.

In the past I have successfully managed to set up a route-based VPN between a physical Check Point cluster and an AWS VPC by following the steps in sk100726, no problems there at all. Now I'm looking to configure something similar to an Azure Virtual Gateway using VTIs, but I'm struggling to find any reference documentation or process like the AWS one.

I've been playing around with it all day and I can't see a way to make it work, and I'm starting to wonder if it even is possible at all. I've looked at sk101275 but I don't think it really applies to what I'm trying to achieve.

Has anyone successfully done this, and if so, how? What other options are there for creating an IPSEC VPN to Azure with a primary/backup configuration? BGP is not really an option in this scenario.

 

Thanks.

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend
0 Kudos
10 Replies
Alex-
Leader Leader
Leader

The Azure VWAN guide is very good, we used it for route-based VPN to Azure VPN gateways and it worked straight away.

0 Kudos
khodgson_bts
Contributor

That seems to require BGP to work though. Have you done it without BGP? What IP's do you assign to the VTI's?

0 Kudos
the_rock
Legend
Legend
0 Kudos
khodgson_bts
Contributor

That looks very promising, thank you. I'll give it go.

the_rock
Legend
Legend

Sounds good!

0 Kudos
the_rock
Legend
Legend

By the way, since you mentioned BGP, I always found the ONLY way to make BGP work through the route based tunnel is to use UNNUMBERED VTIs, meaning it will "piggyback off" the main interface and when you configure it, it will have exact same IP in topology, but nothing to be alarmed about, its 100% normal.

Andy

0 Kudos
khodgson_bts
Contributor

That's good to know. In this case I'm specifically looking to not use BGP. I'll let you know how I get on.

0 Kudos
the_rock
Legend
Legend

I attached doc file with 3 screenshots I took, hope that also helps. Anyway, message me directly if you are not clear and we can do remote.

Andy

 

0 Kudos
khodgson_bts
Contributor

This was very useful; I've managed to get it working. It's really not that different from the AWS process.

Thank you!

0 Kudos
the_rock
Legend
Legend

Of course, glad we can help. Yes, for regular route based, you can use either numbered or unnumbered, but I find using unnumbered is better, as you simply use vti to route the traffic when you create new routes and no need to be setting up new IPs. But again, works either way 🙂

Glad you got it going.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events