SD-WAN Limitations

Limitations that are planned to be resolved:

See sk180605 > section "Limitations".

Limitations by design:

ID

Description

PMTR-115111

SD-WAN is not supported on Spark Firewall Appliances that use two SIM cards for one Cellular connection.

In such a configuration, there are no two Internet Connections working at the same time, but rather a high availability ‎of two Internet connections

PMTR-119509

SD-WAN is not supported on Standalone servers.

PMTR-105895

SD-WAN does not support ClusterXL in the Active-Active mode.

PMTR-105894

SD-WAN does not support ClusterXL in the Load Sharing Unicast mode.

SD-WAN does not support ClusterXL in the Load Sharing Multicast mode.

PMTR-105215

SD-WAN does not support VPN "Overlay" with third-party VPN Peers (Check Point Firewall continues to use the existing Link Selection).

-

SD-WAN Overlay steering is supported only between VPN peers that meet all of these conditions:

  1. Both VPN peers have SD-WAN enabled.

  2. Both VPN peers are managed by the same Check Point Management Server.

  3. Both VPN peers belong to the same Check Point Portal tenant.

  4. Both VPN peers use the same SD-WAN management method (either from SmartConsole, or from Check Point Portal > SD-WAN App).

If any of these conditions is not met, the VPN peers establish VPN tunnels according to the settings configured in SmartConsole > Security Gateway object > IPSec VPN section > Enhanced Link Selection/ Link Selection page.

PMTR-104985

SD-WAN does not support VPN Explicit Multiple Entry Point (MEP) configuration.

PMTR-109701

SD-WAN "Overlay" does not support configuring multiple Center gateways in a Star VPN Community with no satellites, when the "Mesh center gateways" option is enabled.

PMTR-104576

SD-WAN does not support VPN Permanent Tunnels.

PMTR-108281

SD-WAN does not support matching a "Local Breakout" rule to traffic in this scenario:

  1. Traffic matches a Policy Based Routing (PBR) rule that applies to traffic from a local network to "Default", and the next hop in this rule is set to a VPN Tunnel Interface (VTI).

  2. The priority of this PBR rule is lower than 100.