> But you can assign static address/routes for the VPN endpoints, yes?
I have no idea what this means.

When you define your encryption domain under checkpoint, you also define
the firewall it sits behind. That firewall has an IP address. If that IP
address changes for some reason, then your VPN will fail. You also can not
define the same encryption domain behind two different firewalls, at least
easily anyway.

Routing has got nothing to do with most VPN traffic as it is usually
across the Internet and all you are concerned with as a firewall (router)
is the next hop, not VPN gateway that is 5 hops away.

-Don

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to