- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- VPN link selection question
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN link selection question
Hey guys,
I honestly was not even going to post this, but had to, just for my own sanity : - ). Though Im 99.99% sure this is NOT possible, but since customer asked me, figured would pick ya'll brains. So, here is their question...is there ANY way to configure CP firewall (either via link selection or any other way) to use say external IP for specific VPN tunnels and then use a different IP for other tunnels?
Cheers.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the past this was possible via entry in user.def see Controlling which IP address VPN traffic passes through But I think ther‘s no support for this in the newer releases.
With link selection you can achieve this if the remote VPN gateways are available via different interface. You can route tunnel A via interface A and tunnel B via interface B, it depends on routing configuration. Source IP will be the interface IP of the outgoing interface. How to create VPN tunnels to a 3rd party peer using a specific ISP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the past this was possible via entry in user.def see Controlling which IP address VPN traffic passes through But I think ther‘s no support for this in the newer releases.
With link selection you can achieve this if the remote VPN gateways are available via different interface. You can route tunnel A via interface A and tunnel B via interface B, it depends on routing configuration. Source IP will be the interface IP of the outgoing interface. How to create VPN tunnels to a 3rd party peer using a specific ISP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @Wolfgang ! Never seen that sk before, but good to know, though I believe you are right, probably not supported in new versions. For your 2nd point, customer has only 1 external interface, so not sure that might be feasible. What about below setting, would this work possibly?
Thoughts?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@the_rock the shown settings are for the IP addresses they will be probed from the remote gateway to the local gateway (see description in the top) Additional you have to configure the IP address of the outgoing packets, second part of your shown screen. But I think your need does not work if all tunnel packets are going through the same interface.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks mate, I think what you gave is the closest to what they need, so I greatly appreciate it 🙌🙌
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can configure Remote Access and Site-to-Site VPN tunnels with a different "Link Selection" IP.
However, you cannot configure "per peer" Link Selection, which is what it sounds like your customer wants.
Though sk31102 does seem like it would support that (if it works on current versions).
FYI, in R82, I believe we are overhauling the whole "Link Selection" mechanism.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fair enough, thank you. Its weird how this client has route based tunnels configured (never seen that in 15 years with CP), so makes it a bit tricky to do all this, but you guys gave me excellent choice, so I will give this to them, probably tomorrow or some time next week. They understand the situation, so really this is the best they can get, whether they like it or not 😊
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @PhoneBoy ...I assume you were referring to visitor mode setting for remote access where it lets you select the interface?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, I'm referring to: https://support.checkpoint.com/results/sk/sk32229
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, right...I remember seeing this sk couple of years ago.
