- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
we have 3ISP topology as external. One ISP link we have configure for vpn site to site.Already running 8 vpn tunnels.
link selection we have manually selected that particular ISP from interface ip link.
we have need to create new vpn with tunnel using another external ISP connection. We are not enabled isp redundancy. If we selected new interface in link selection existing vpns will down.
Can anyone advice what will happen if we select vpn link selection Main Address? Any issues if configured 2ISP with these method?
thank you!
Main Address will always use the object IP for the VPN.
If you want the IP to change based on ISP used, ISP Redundancy must be enabled.
Hi PhoneBoy,
I remember got one scenario with some issues, where setup as
<Multiple Router> - <Link Controller/Load Balancer> -Transit Link / Internal IP- <Check Point Gateway>
Where Check Point will only have one Link Selection option for NATed Public IP Address selection, if have multiple Public IP Address, we got any options to include multiple Public IP Address?
Unfortunately, you can only specify one IP in Link Selection currently.
This is something I believe we will address in an upcoming release.
I think that would be HUGE improvement, if it happens.
There is no issue doing it the way you said...Im sure thats how 99% of people do it, BUT, as Phoneboy said, if you want this to change based on ISP itself, then you have to use ISP redundancy. Important note, keep in mind that even IF you use ISPR, thats no guarantee if there is a failover, vpn tunnels will work, as other ends would need to know about the new external IP on CP side, so thats also something to keep in mind.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY