> Source: [sk174228](https://support.checkpoint.com/results/sk/sk174228)

# sk174228 - Scalable Platforms major VPN enhancements

| Property | Value |
|----------|-------|
| Solution ID | sk174228 |
| Date Created | 2021-06-28 |
| Last Modified | 2021-06-30 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

Starting from Jumbo Hotfix Accumulator for R81 Take_34, Scalable Platforms are aligned with the following standard Security Gateway features:   

* VPN Tunnel Interface (VTI)
  * Route Based VPN
  * Enable BGP and OSPF Dynamic Routing Protocols on VTIs

<!-- -->

* Tunnel Management - Permanent Tunnels
  * Tunnel Testing for Permanent Tunnels
  * Dead Peer Detection (DPD)
* Link Selection
  * Service Based Link Selection ([sk56384](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk56384))
  * IP Selection by Remote Peer
    * High Availability
    * Load Sharing
  * Outgoing Route Selection
    * Route-based probing
* Back-to-back tunnels (hub and spokes)
  * Maestro as a Center in a Star community - Satellite peers can communicate with each other through the Center
  * Client-to-Site Traffic over a Site-to-Site VPN Tunnel **(Client \> Maestro \> Peer \> resource)**
  * Client to Site to Client through a Maestro Gateway**(Client \> Maestro \> Client)**
* VPN local connections originated from Maestro SGMs
  * Initiate a connection from an SGM if the connection's destination requires encryption
  * Identity Awareness via VPN - The Identity Source (users database) can be located across a VPN tunnel (especially in the cloud).

Note that due to major design changes, an upgrade from Jumbo Hotfix Accumulator for R81 (lower than Take_34) to Jumbo Hotfix Accumulator for R81 (Take_34 and higher) requires a maintenance window, because VPN traffic impact is expected.  
**Note that all SGMs should run on Jumbo Hotfix Accumulator for R81 Take_34 and higher (running with incompatible versions can cause VPN traffic impact).**   

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
