- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Do I need to create manually Site-Site tunnels...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do I need to create manually Site-Site tunnels with firewalls before SDWAN
Hi Team,
Wondering if I need to configure Site-Site VPN on management server through smart console before I configure the SDWAN beween firewalls? Will that be Mesh topology?
Or SDWAN agent will configure the tunnels on its own?
Blason R
CCSA,CCSE,CCCS
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently you can have SD-WAN Overlay only between firewalls managed by the same Management server (on the roadmap in between different Domains in MDM server).
the authentication will be based on certificate as today. we don't change that.
if there is already VPN tunnel between those gateways, once you enable SD-WAN on those peers (both sides), the tunnels will be changed from link selection to tunnel per interface by SD-WAN.
if everything is configured properly in advance, the switch should be quick.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
we are based on the management server for VPN Configuration.
VPN Configuration still managed in the Smart Console. once there is VPN between peers, the SD-WAN build tunnel per interface between the peers (replace the GW OBJECT > IPSEC VPN > Link selection), and will apply the SD-WAN overlay on top of it.
the community can be either mesh or star.
you can learn more here:
https://support.checkpoint.com/results/sk/sk180605
feel free to ask more questions.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And what if the tunnel is already there between peer? Plus what would happen if the same management server is managing those firewalls? In that case it will be a certificate based IPSEC vpn. Will that work seamlessly?
Blason R
CCSA,CCSE,CCCS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Currently you can have SD-WAN Overlay only between firewalls managed by the same Management server (on the roadmap in between different Domains in MDM server).
the authentication will be based on certificate as today. we don't change that.
if there is already VPN tunnel between those gateways, once you enable SD-WAN on those peers (both sides), the tunnels will be changed from link selection to tunnel per interface by SD-WAN.
if everything is configured properly in advance, the switch should be quick.