Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
h3xRaider
Explorer

Multiple Link auto failover VPN over Internet Link and non VPN access on MPLS

Hi Folks,

I have R80.40 with two cluster members both connecting to MPLS and ILL links individually. Now I am required to use MPLS for all internal traffic and ILL link for internet traffic.

If the MPLS link fails then ILL link should be selected as active, and all outgoing traffic should be routed through VPN tunnel, and whence the MPLS link is up we should fallback for internal traffic to MPLS link from ILL and VPN tunnel which was previously established should not be used.

ILL link cannot be used for VPN traffic when MPLS link is active.

Thanking All!!

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

Are both sides of the VPN Check Point gateways?

Have you considered route-based VPNs or discussed SD-WAN with your local SE....

CCSM R77/R80/ELITE
0 Kudos
AmirArama
Employee
Employee

Hi,

you can consider route based VPN to prioritize MPLS path in clear, and lower path to vti (link selection over internet link).

you can consider configuring trusted links as described here: https://support.checkpoint.com/results/sk/sk56384

if the customer is willing to encrypt even on top of the MPLS, you can consider our Quantum SD-WAN solution to get added value capabilities such as seamless failover. 

0 Kudos
h3xRaider
Explorer

Thanks I will try to simulate the solution. Is there easy guide for route based VPN, I have checked

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VP...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events