<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN routing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15386#M1084</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your QUESTIONs:&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; 1. How can we check by CLI the routes created by VPN Routing from Start COmmunity&lt;/P&gt;&lt;P&gt;You can found policy based VPN routes in the following tabel "&lt;SPAN style="color: #000000;"&gt;fw tab -f -t vpn_routing -u&lt;/SPAN&gt;" or use te one liner from my articel:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3021"&gt;Show VPN Routing on CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; 2. Could you explain us how is the orden in a VPN routing&lt;/P&gt;&lt;P&gt;Here you can find a flowchart of how VPN decryption and encryption is implemented:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; 3. Do you know how other troubleshooting could we run?&lt;/P&gt;&lt;P&gt;See answer from &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc&lt;/A&gt;&amp;nbsp; &amp;gt; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" rel="nofollow"&gt;Debugging Site-to-Site VPN&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Aug 2018 21:53:47 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2018-08-03T21:53:47Z</dc:date>
    <item>
      <title>VPN routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15384#M1082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;***********************&lt;BR /&gt;ENVIRONMENT&lt;/P&gt;&lt;P&gt;VPN COMMUNITY TYPE: Star&lt;BR /&gt;CENTER GW: CheckPoint R80.10 (appliances 5900) (manage our customer)&lt;BR /&gt;SATELLITE GW: Cisco (manage external 1)&lt;BR /&gt;SATELLITE GW: Fortinet (manage external 2)&lt;BR /&gt;SATELLITE GW: Cisco ASA (manage external 3)&lt;BR /&gt;SATELLITE GW: Checkpoint (manage external 4)&lt;/P&gt;&lt;P&gt;**************************&lt;BR /&gt;TRAFFIC FLOW&lt;/P&gt;&lt;P&gt;SATELLITE GW from external 2, 3 y 4 needs to contact to SATELLITE GW external 1, the traffic must always pass through CENTER GW.&lt;/P&gt;&lt;P&gt;*************************&lt;BR /&gt;CONFIGURATION&lt;/P&gt;&lt;P&gt;Each SATELLITE (2,3,4) arrive to CENTER GW with a follow IP address&lt;BR /&gt;customer 2 --&amp;gt; 10.10.10.10 &lt;BR /&gt;customer 3 --&amp;gt; 10.10.10.15 &lt;BR /&gt;customer 4 --&amp;gt; 10.10.10.20 &lt;BR /&gt;they try to connect to 172.25.107.193 (host behid SATELLITE GW: Cisco (manage external 1))&lt;/P&gt;&lt;P&gt;When &lt;BR /&gt;Host 10.10.10.10-SATELLITE GW: Fortinet (manage external 2) AND host10.10.10.20-SATELLITE GW: Checkpoint (manage external 4) did the telnet connection to 172.25.107.193-SATELLITE GW: Cisco (manage external 1) EVERITHING WORKS FINE&lt;/P&gt;&lt;P&gt;When&lt;BR /&gt;Host 10.10.10.15-SATELLITE GW: Cisco (manage external 3) did the telnet connection to 172.25.107.193-SATELLITE GW: Cisco (manage external 1) DOES NOT OPEN&lt;/P&gt;&lt;P&gt;******************************&lt;BR /&gt;LOGS&lt;BR /&gt;1. When the traffic works fine between satellites the log traffic show action VPN Routig&lt;BR /&gt;2. When the traffic does no work the log traffci show action DECRIPT (never show VPN Routing)&lt;/P&gt;&lt;P&gt;*******************&lt;BR /&gt;QUESTION&lt;/P&gt;&lt;P&gt;1. How can we check by CLI the routes created by VPN Routing from Start COmmunity&lt;BR /&gt;2. Could you explain us how is the orden in a VPN routing &lt;BR /&gt; First decript&lt;BR /&gt; Second Nat&lt;BR /&gt; Third Encript&lt;BR /&gt;3. Do you know how other troubleshooting could we run?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2018 19:05:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15384#M1082</guid>
      <dc:creator>Sandra_Suarez</dc:creator>
      <dc:date>2018-08-02T19:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15385#M1083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A lot of the troubleshooting for site-to-site VPN is here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467"&gt;Debugging Site-to-Site VPN&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2018 22:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15385#M1083</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-02T22:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15386#M1084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your QUESTIONs:&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; 1. How can we check by CLI the routes created by VPN Routing from Start COmmunity&lt;/P&gt;&lt;P&gt;You can found policy based VPN routes in the following tabel "&lt;SPAN style="color: #000000;"&gt;fw tab -f -t vpn_routing -u&lt;/SPAN&gt;" or use te one liner from my articel:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3021"&gt;Show VPN Routing on CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; 2. Could you explain us how is the orden in a VPN routing&lt;/P&gt;&lt;P&gt;Here you can find a flowchart of how VPN decryption and encryption is implemented:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; 3. Do you know how other troubleshooting could we run?&lt;/P&gt;&lt;P&gt;See answer from &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc&lt;/A&gt;&amp;nbsp; &amp;gt; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" rel="nofollow"&gt;Debugging Site-to-Site VPN&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A _jive_internal="true" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2018 21:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/15386#M1084</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-03T21:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/60913#M4655</link>
      <description>&lt;P&gt;Hi HeiKo,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would you please help me to understand. Does routing is required for remote end n/w&amp;nbsp; in IPSec VPN?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2019 05:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing/m-p/60913#M4655</guid>
      <dc:creator>AnujPratap</dc:creator>
      <dc:date>2019-08-22T05:04:03Z</dc:date>
    </item>
  </channel>
</rss>

