Loading

How to Configure Anypoint VPN with a Check Point Cluster

Data pubblicazione: Jul 25, 2025
Operazione

GOAL

Each Anypoint VPN connection consists of two endpoints on the MuleSoft side. When configuring an Anypoint VPN connection, you have the ability to specify a single remote IP address - the public IP address of your VPN endpoint - as the VPN peer. When using a Check Point cluster, the VPN peer is the logical cluster rather than a physical member device, so connectivity to a cluster can be achieved with a single VPN connection. This article provides the configuration steps for Anypoint VPN with a Check Point cluster.

Important: This Knowledge Article aims to provide basic guidelines for configuring Anypoint VPN with Check Point clusters. The contents of the article are to be used at your own risk and are provided as-is. For further information on configuring Check Point clusters, please reach out to Check Point support. 


 

Fasi
  • A Check Point cluster refers to two or more devices that work together to provide redundancy.  For this type of setup you will need additional IP addresses for the tunnel interfaces, and these will not be defined in the config file.
  • All configuration files from Runtime Manager specify a /30 subnet for each tunnel. It is not possible to expand that subnet to include additional addresses, but it is also not necessary. 
  • The Point-to-Point IP addresses are used for "cluster interfaces" only.
  • You will need to assign another unique IP for each of the "member interfaces".
  • This Check Point article explains the steps in more detail: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100726

NOTE: From the Check Point perspective, the VTI Local Address for each cluster member, is not the address provided in the configuration file.
Numero articolo Knowledge

001116865

 
Caricamento
Salesforce Help | Article