<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Connectivity to S2S connected sites in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205430#M4584</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am a little stuck again, appreciate your help here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a CP setup in Azure. From there we have a simple setup.&amp;nbsp; one S2S connection to a 3rd party network (who have their phase to set to ANY apparently) (not Checkpoint on the other end).&amp;nbsp; That works fine. All the systems that we have connected to the CP can connect over the S2S both ways.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we are struggling with is that we need our users who connect to our CP over Check Point mobile vpn to be able to route to that same network over the S2S.&amp;nbsp; &amp;nbsp; We tried adding it as one of the trusted networks but i think it broke the S2S connection.&amp;nbsp; &amp;nbsp; Is there a way to publish the routes and allow communication ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you need more info, as i may not have provided enough detail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 07:38:12 GMT</pubDate>
    <dc:creator>TonyM12</dc:creator>
    <dc:date>2024-02-08T07:38:12Z</dc:date>
    <item>
      <title>VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205430#M4584</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am a little stuck again, appreciate your help here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a CP setup in Azure. From there we have a simple setup.&amp;nbsp; one S2S connection to a 3rd party network (who have their phase to set to ANY apparently) (not Checkpoint on the other end).&amp;nbsp; That works fine. All the systems that we have connected to the CP can connect over the S2S both ways.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we are struggling with is that we need our users who connect to our CP over Check Point mobile vpn to be able to route to that same network over the S2S.&amp;nbsp; &amp;nbsp; We tried adding it as one of the trusted networks but i think it broke the S2S connection.&amp;nbsp; &amp;nbsp; Is there a way to publish the routes and allow communication ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you need more info, as i may not have provided enough detail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 07:38:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205430#M4584</guid>
      <dc:creator>TonyM12</dc:creator>
      <dc:date>2024-02-08T07:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205431#M4585</link>
      <description>&lt;P&gt;Route based or domain based tunnel? If it is domain based you need to add the mobile access IP range to your own encryption domain. Then the Azure side needs to do the same or it could indeed break the tunnel.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 07:49:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205431#M4585</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-08T07:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205437#M4586</link>
      <description>&lt;P&gt;Hi Lesley,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its route based.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i didnt mention is that there are 2 S2S tunnels in the same community. so it acts as an active active scenario.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our side is checkpoint, the other side is Juniper.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last time i added the S2S range to our VPN route (i probably did it wrong) it broke connectivity to the S2S.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 10:04:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205437#M4586</guid>
      <dc:creator>TonyM12</dc:creator>
      <dc:date>2024-02-08T10:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205443#M4587</link>
      <description>&lt;P&gt;quick and dirty just NAT your remote access network behind an IP that currently works for that tunnel.&lt;BR /&gt;&lt;BR /&gt;The problem seems to be that the remote gateway doesn't "know" about your RA net.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 09:35:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205443#M4587</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2024-02-08T09:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205476#M4588</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87513"&gt;@Machine_Head&lt;/a&gt;&amp;nbsp;. How is this setting configured?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24420i7FDB6417EC22F005/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 14:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205476#M4588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T14:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205484#M4589</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;Its set the same as your screenshot.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 14:54:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205484#M4589</guid>
      <dc:creator>TonyM12</dc:creator>
      <dc:date>2024-02-08T14:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205485#M4590</link>
      <description>&lt;P&gt;For the reference, here is what options do.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 08 Feb 2024 15:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205485#M4590</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T15:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205525#M4591</link>
      <description>&lt;P&gt;Have you added the 3rd party networks to the Remote Access encryption domain?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 22:37:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205525#M4591</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-02-08T22:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205553#M4592</link>
      <description>&lt;P&gt;I figured it out.&amp;nbsp; The 3rd party network was set to 0.0.0.0 on their side, and we have limited it.&amp;nbsp; &amp;nbsp;Once we set it the same, it worked.&amp;nbsp; &amp;nbsp; Appreciate your help guys.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 08:17:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205553#M4592</guid>
      <dc:creator>TonyM12</dc:creator>
      <dc:date>2024-02-09T08:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Connectivity to S2S connected sites</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205576#M4594</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 12:13:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/VPN-Connectivity-to-S2S-connected-sites/m-p/205576#M4594</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-09T12:13:18Z</dc:date>
    </item>
  </channel>
</rss>

