Here is an example how this works with Azure.
Instead of Azure, this can also be any other VPN destination.
1) Create VPN Tunnel Interface (VTI)
![HeikoAnkenbrand_0-1680463156508.png HeikoAnkenbrand_0-1680463156508.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20368iB31BBADD40C37555/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_1-1680463156510.png HeikoAnkenbrand_1-1680463156510.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20369i07763FD8DD806142/image-size/medium?v=v2&px=400)
NOTE:
THE PEER NAME MUST MATCH THE SMARTDASHBOARD OBJECT NAME OTHERWISE THE VTI WILL NOT WORK
2) Add Static Route for Azure VPN Peer BGP IP:
![HeikoAnkenbrand_2-1680463156514.png HeikoAnkenbrand_2-1680463156514.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20370iCE5CB270946DD8A9/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_3-1680463156515.png HeikoAnkenbrand_3-1680463156515.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20372i9FB95DA18A76BEA2/image-size/medium?v=v2&px=400)
3) Setup BGP in GAIA WebUI
WARNING:
Without “ALL” of these configurations completed BGP will not be successful
![HeikoAnkenbrand_4-1680463156518.png HeikoAnkenbrand_4-1680463156518.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20374i1543A93E46503997/image-size/medium?v=v2&px=400)
4) Add Azure Gateway BGP Information:
![HeikoAnkenbrand_5-1680463156520.png HeikoAnkenbrand_5-1680463156520.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20371i3EA23C6D24180E85/image-size/medium?v=v2&px=400)
Fill in information based on Azure Gateway BGP Settings:
![HeikoAnkenbrand_6-1680463156521.png HeikoAnkenbrand_6-1680463156521.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20377i4F4C4582DD2DA436/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_7-1680463156522.png HeikoAnkenbrand_7-1680463156522.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20376i2256A6736D031C46/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_8-1680463156524.png HeikoAnkenbrand_8-1680463156524.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20375iDB7560850DDF67FC/image-size/medium?v=v2&px=400)
NOTE:
Without Multihop enabled the BGP session will not be established
5) Set BGP Inbound route filters
![HeikoAnkenbrand_9-1680463156526.png HeikoAnkenbrand_9-1680463156526.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20379iDC348C621161DC00/image-size/medium?v=v2&px=400)
NOTE:
For the purpose of this documentation the inbound filter has been set to accept all routes – this will vary in each environment
6) Set inbound route filter settings
![HeikoAnkenbrand_10-1680463156528.png HeikoAnkenbrand_10-1680463156528.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20378i6C428595A610B550/image-size/medium?v=v2&px=400)
7) Create an empty VPN group which will represent the Azure VPN Gateway’s vpn domain:
![HeikoAnkenbrand_11-1680463488594.png HeikoAnkenbrand_11-1680463488594.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20380iE82A4EF98EA9870B/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_12-1680463488595.png HeikoAnkenbrand_12-1680463488595.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20382iE36F7A3CFE898345/image-size/medium?v=v2&px=400)
8 ) Next create Azure VPN Gateway object:
![HeikoAnkenbrand_13-1680463488596.png HeikoAnkenbrand_13-1680463488596.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20381i7B0E2C33EFB0A8CC/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_15-1680463488600.png HeikoAnkenbrand_15-1680463488600.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20385iF63F4105BA339575/image-size/medium?v=v2&px=400)
9) Create VPN Community
![HeikoAnkenbrand_16-1680463488602.png HeikoAnkenbrand_16-1680463488602.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20384i97E7DB8DBA6B8375/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_25-1680463669045.png HeikoAnkenbrand_25-1680463669045.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20386iAB101D2CBE646803/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_26-1680463669048.png HeikoAnkenbrand_26-1680463669048.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20388iFE9B2B53CD9CC0F9/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_27-1680463669050.png HeikoAnkenbrand_27-1680463669050.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20387iE3FFCA85065C0EAA/image-size/medium?v=v2&px=400)
![HeikoAnkenbrand_28-1680463669053.png HeikoAnkenbrand_28-1680463669053.png](https://community.checkpoint.com/t5/image/serverpage/image-id/20389i37E2CBD6874D27B5/image-size/medium?v=v2&px=400)
10) Create VPN ruleset
...
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips