- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Evening all. I'm hopeful that someone can help me with this.
In the past I have successfully managed to set up a route-based VPN between a physical Check Point cluster and an AWS VPC by following the steps in sk100726, no problems there at all. Now I'm looking to configure something similar to an Azure Virtual Gateway using VTIs, but I'm struggling to find any reference documentation or process like the AWS one.
I've been playing around with it all day and I can't see a way to make it work, and I'm starting to wonder if it even is possible at all. I've looked at sk101275 but I don't think it really applies to what I'm trying to achieve.
Has anyone successfully done this, and if so, how? What other options are there for creating an IPSEC VPN to Azure with a primary/backup configuration? BGP is not really an option in this scenario.
Thanks.
See if below posts I made and responded to help. If not, message me, I have done this few times.
Andy
The Azure VWAN guide is very good, we used it for route-based VPN to Azure VPN gateways and it worked straight away.
That seems to require BGP to work though. Have you done it without BGP? What IP's do you assign to the VTI's?
See if below posts I made and responded to help. If not, message me, I have done this few times.
Andy
That looks very promising, thank you. I'll give it go.
Sounds good!
By the way, since you mentioned BGP, I always found the ONLY way to make BGP work through the route based tunnel is to use UNNUMBERED VTIs, meaning it will "piggyback off" the main interface and when you configure it, it will have exact same IP in topology, but nothing to be alarmed about, its 100% normal.
Andy
That's good to know. In this case I'm specifically looking to not use BGP. I'll let you know how I get on.
This was very useful; I've managed to get it working. It's really not that different from the AWS process.
Thank you!
Of course, glad we can help. Yes, for regular route based, you can use either numbered or unnumbered, but I find using unnumbered is better, as you simply use vti to route the traffic when you create new routes and no need to be setting up new IPs. But again, works either way 🙂
Glad you got it going.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
11 | |
7 | |
6 | |
6 | |
6 | |
6 | |
4 | |
4 | |
4 |
Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyThu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY