<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route Incoming external traffic over VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98713#M10340</link>
    <description>&lt;P&gt;If it’s from a specific IP in the encryption domain,&amp;nbsp;&lt;BR /&gt;it sounds like a bug.&lt;BR /&gt;You might want to engage with the TAC.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Oct 2020 15:16:44 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-10-10T15:16:44Z</dc:date>
    <item>
      <title>Route Incoming external traffic over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98397#M10337</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am struggling with routing external incoming traffic that is coming from the External Interface via a VPN tunnel?&lt;/P&gt;&lt;P&gt;The traffic flow should be:&lt;/P&gt;&lt;P&gt;External IP --&amp;gt; External GW published IP&amp;nbsp; --&amp;gt; Static NAT to internal dst IP --&amp;gt; VPN Tunnel --&amp;gt; dst&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To explain shortly - incoming traffic from external IP is hitting the GW published IP (via Proxy ARP) and NATed to an internal address which should be routed via the VPN.&lt;/P&gt;&lt;P&gt;I added the External IP address to the VPN domain but still the Traffic is not routed over the VPN but going out back via the external interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a static NAT to translate the external dst IP address to the Internal dst IP address which should go to the VPN&amp;nbsp;&lt;/P&gt;&lt;P&gt;External IP --&amp;gt; External GW&amp;nbsp; IP&amp;nbsp;&lt;/P&gt;&lt;P&gt;External IP --&amp;gt; Internal dst IP&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;however the traffic goes back via the External Interface&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any SK or a idea how to tackle this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 10:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98397#M10337</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2020-10-07T10:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Route Incoming external traffic over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98690#M10338</link>
      <description>&lt;P&gt;The decision to encrypt is based on the source IP being in the encryption domain, which I'm guessing is not the case here.&lt;BR /&gt;Perhaps with a route-based VPN and a null encryption domain, you could make this work.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 23:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98690#M10338</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-09T23:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Route Incoming external traffic over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98698#M10339</link>
      <description>&lt;P&gt;Hi PB,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The traffic is coming from external interface and although I added the External Incoming IP to the VPN domain it is still not routed via the tunnel. I guess the VPN topology doesn't include external address for a reason (or a bug in the VPN topology calculation). I tried to find any SK about routing external traffic via internal VPN but couldn't find anything useful&lt;/P&gt;&lt;P&gt;I was trying to avoid route-based VPN but I guess this is the only way so I will have a look at it&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your answer&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 10:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98698#M10339</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2020-10-10T10:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Route Incoming external traffic over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98713#M10340</link>
      <description>&lt;P&gt;If it’s from a specific IP in the encryption domain,&amp;nbsp;&lt;BR /&gt;it sounds like a bug.&lt;BR /&gt;You might want to engage with the TAC.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Oct 2020 15:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/98713#M10340</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-10T15:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Route Incoming external traffic over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/127951#M18585</link>
      <description>&lt;P&gt;Hello Shahar,&lt;/P&gt;&lt;P&gt;Did you solved this by using route-based VPN or did you still used domain-based for this?&lt;/P&gt;&lt;P&gt;Tia&lt;/P&gt;&lt;P&gt;Lesley&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 09:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Incoming-external-traffic-over-VPN/m-p/127951#M18585</guid>
      <dc:creator>Wille010</dc:creator>
      <dc:date>2021-08-25T09:54:58Z</dc:date>
    </item>
  </channel>
</rss>

