<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing processing order (VPN, PBR, Routing Table) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81085#M11322</link>
    <description>&lt;P&gt;Can you elaborate of the use case?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2020 07:49:24 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-04-07T07:49:24Z</dc:date>
    <item>
      <title>Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81077#M11321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would like to know the order of processing routes in a security gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Main purpose is to apply PBR rules on traffic that decrypted from site to site VPN or from VPN Routing. is this possible?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81077#M11321</guid>
      <dc:creator>51ce833e-a8ec-4</dc:creator>
      <dc:date>2020-04-07T07:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81085#M11322</link>
      <description>&lt;P&gt;Can you elaborate of the use case?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:49:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81085#M11322</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T07:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81086#M11323</link>
      <description>&lt;P&gt;Anyhow,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a quote from&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100500" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100500&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following features/blades are&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;supported with PBR:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;IPv6&lt;/LI&gt;
&lt;LI&gt;URL Filtering&lt;/LI&gt;
&lt;LI&gt;IPS&lt;/LI&gt;
&lt;LI&gt;Locally-generated traffic&lt;/LI&gt;
&lt;LI&gt;Security Servers&lt;/LI&gt;
&lt;LI&gt;Data Loss Prevention (DLP) blade&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;U&gt;VPN Domain Based&lt;/U&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;U&gt;VPN Route Based&lt;/U&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Anti-Spam blade&lt;/LI&gt;
&lt;LI&gt;Mail Transfer Agent (MTA) (relevant for Threat Emulation/Threat Extraction/Data Loss Prevention/Anti-Spam blades)&lt;/LI&gt;
&lt;LI&gt;ISP Redundancy&lt;/LI&gt;
&lt;LI&gt;The following applications (which use Check Point Active Streaming [CPAS]):&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;VoIP (H323, SIP, Skinny, etc.)&lt;/LI&gt;
&lt;LI&gt;HTTPS Inspection&lt;/LI&gt;
&lt;LI&gt;HTTP Header Spoofing&lt;/LI&gt;
&lt;LI&gt;HTTP Proxy&lt;/LI&gt;
&lt;LI&gt;IMAP in IPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 07 Apr 2020 07:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81086#M11323</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T07:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81090#M11324</link>
      <description>I'm trying to implement site to site VPN and avoid asymmetric routing.&lt;BR /&gt;Let's say we have two sites connected through a GW cluster each site, both managed by the same Security Management.&lt;BR /&gt;&lt;BR /&gt;VPN FWs are connected (via switch) to Core FW (which acts as the default gateway in the network) at each site&lt;BR /&gt;&lt;BR /&gt;VPN FWs are also directly connected to each segment in the network to reduce traffic on Core FW&lt;BR /&gt;&lt;BR /&gt;traffic between VPN domains in this case is going through asymmetric paths and it makes applications go slow (or even not work)&lt;BR /&gt;&lt;BR /&gt;I would like to force traffic between VPN domains to be routed to the Core FW regardless of directly connected subnets in the system routing table&lt;BR /&gt;&lt;BR /&gt;I hope this was clear because I know it's not a usual use-case.</description>
      <pubDate>Tue, 07 Apr 2020 08:17:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81090#M11324</guid>
      <dc:creator>51ce833e-a8ec-4</dc:creator>
      <dc:date>2020-04-07T08:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81093#M11325</link>
      <description>&lt;P&gt;Okay, that makes sense. Unfortunately, you cannot do PBR and VPN on the same box. What is feasible is breaking VPN tunnel on another device and then send traffic to PBR box. You can actually achieve this with VSX.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 08:28:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81093#M11325</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-04-07T08:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81094#M11326</link>
      <description>Thank you very much !</description>
      <pubDate>Tue, 07 Apr 2020 08:30:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/81094#M11326</guid>
      <dc:creator>51ce833e-a8ec-4</dc:creator>
      <dc:date>2020-04-07T08:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/98066#M11327</link>
      <description>&lt;P&gt;Hello Val,&lt;/P&gt;&lt;P&gt;do the restrictions to PBR just hit the networks/IP-Range/IF touched by PBR or have these restrictions impact to the whole gateway?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 10:39:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/98066#M11327</guid>
      <dc:creator>r31N3r</dc:creator>
      <dc:date>2020-10-02T10:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Routing processing order (VPN, PBR, Routing Table)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/98075#M11328</link>
      <description>&lt;P&gt;Whole GW&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 12:03:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-processing-order-VPN-PBR-Routing-Table/m-p/98075#M11328</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-02T12:03:53Z</dc:date>
    </item>
  </channel>
</rss>

