Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ajsingh
Explorer

Backup vpn tunnel to Azure when Express route is Primary

Hi all,

I am attempting to establish a backup VPN link from on-premises to our Azure tenant. Currently, I have Check Point (CP) FW version r81.10 configured as follows: CP FW ----> MPLS ----> Express Route ----> Azure.

I would like to set up a VPN from the CP firewall to Azure (with BGP, I presume) to achieve redundancy.

Is it possible with Check Point firewalls? If yes, should I be using BGP? Could I receive some guidance or steps from someone who has already done this or has knowledge on this matter, please?

Any help is greatly appreciated.

0 Kudos
3 Replies
the_rock
Legend
Legend

My colleague and I actually have same scenario with the customer and MS support sent them something that we are trying to verify would work in their case. Will keep you posted on what we find.

I am fairly sure it is possible and yes, you need BGP, for sure. It really boils down to these things:

-xpress route is ALWAYS preferred

-VPN will be preferred IF prefix is shorter, so say /17 over /16 subnet

Andy

0 Kudos
ajsingh
Explorer

Thank you. I will wait 🙂

0 Kudos
the_rock
Legend
Legend

Customer included us on the email thread with Azure support, so lets see what they say 🙂

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events