- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
You can't do it this way.
* Domain based VPNs take precedence over route-based VPNs. If you have multiple communities, (some route-based, some domain-based), *AND* there's a chance of a pair of networks overlapping across the communities, then a domain-based VPN will be attempted.
* You can't have a VPN community with GwA having a VPN domain [with objects] defined, and GwB an empty VPN domain. This won't trigger the route-based VPN domain code.
* Route-based VPNs need to be IKEv2 with Universal Tunnels (One subnet per gateway pair), for best effects (yes you can do it with IKEv1 but it's not as compatible; just avoid it).
* You mention cluster, with BGP, so you'll want to consider:
The static route establishes reachability to the BGP peer loop00 (because the eBGP peer is now 2 hops away).
Using loop00 VIP for eBGP on route-based VPNs is the best way to go. You can then build your routemap policies as needed.
You can even enable BFD (ip-reachability-detection) for the BGP peers; be sure to use "ip-reachability-detection multihop local-address <ip of loop00>" on the BGP configuration. This is because BFD must originate from the BGP peer IP.
Tread carefully with mixing route-based and domain-based VPNs. You'll almost certainly want to use Encryption Domains per Community instead:
* Edit community
* Click on a gateway in the list
* Click the pencil icon (or double-click) to open a new VPN domain window for the gateway
You can choose a new VPN domain group to be active per community. This has some other limitations, but overall it works well.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY