<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN routing between 3rd party A VTI VPN --&amp;gt; CP --&amp;gt; 3rd Party Domain based VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/83526#M11391</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;This did work with the help of the R80.40 different Encryption domains for each community. (could not do it without this)&lt;/P&gt;&lt;P&gt;Also used the vpn_route.conf to allow the inter vpn routing on the Check Point Hub Gateway. (only for traffic to go into the Domain based VPN - the VTI just worked with routing.)&lt;/P&gt;&lt;P&gt;No nat necessary but obviously the correct routing was required on both the 3rd party VTI VPN side and the 3rd party Domain based side.&lt;/P&gt;&lt;P&gt;Very impressed this worked:-) Love R80.40 now!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First time I have ever seen the VPN routing Icon --great stuff!!&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 18:44:31 GMT</pubDate>
    <dc:creator>Darren_Fine</dc:creator>
    <dc:date>2020-04-28T18:44:31Z</dc:date>
    <item>
      <title>VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82681#M11387</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have a client who has 2 vpns between 3rd parties like so :&lt;/P&gt;&lt;P&gt;1) VTI route based VPN between 3rd party (SiteA) and (HUB CP Gateway) (own star vpn community)&lt;/P&gt;&lt;P&gt;(SiteA- 10.0.0.0/13) ----routed VTI-------- (HubCPgateway - 172.16.9.0/24)&lt;/P&gt;&lt;P&gt;2) Domain based VPN between 3rd party (SiteC)and (HUB CP Gateway) (own star vpn community) (using one tunnel per Gateway setting)&amp;nbsp;&lt;/P&gt;&lt;P&gt;(HubCPgateway - 172.16.9.0/24) ----Domain Based VPN---(SiteC- 10.200.0.0/19)&lt;/P&gt;&lt;P&gt;Now for whatever reason the client wants to route traffic between the two third party sides (they own the equipment at the 3rd party sites and need to replicate).&lt;/P&gt;&lt;P&gt;So wants Site A and SiteC to talk via HubCPGateway like so :&lt;/P&gt;&lt;P&gt;(SiteA- 10.0.0.0/13)-------routed--VTI------(HubCPgateway- 172.16.9.0/24)-------Domain Based VPN------(SiteC- 10.200.0.0/19)&lt;/P&gt;&lt;P&gt;I tried to ADD the networks in SiteC into HUB CPGateways encryption domain and just route the traffic from SITEA via the routed VTI . The traffic does come down the vpn but then gives the traffic gives the error "according to policy packet should not have been decrypted " .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also tried to ADD networks in SiteC and SiteA into HUB CPGateways encryption domain this made no difference. I was thinking that R80.40 which allows for different encryption domains per vpn community may assist me with this.&lt;/P&gt;&lt;P&gt;(or do I need to change a user.def file ? )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did see a whole section in the manual where they use the vpn_route.conf file to route traffic between vpns but in that scenario all the gateways were CP gateways and managed by the same Management station.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to do it with R80.30 ? If yes how ?&lt;/P&gt;&lt;P&gt;If not do you think it will be possible with R80.40 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 21:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82681#M11387</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2020-04-21T21:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82714#M11388</link>
      <description>You're talking about route-based VPN and Encryption Domains.&lt;BR /&gt;The encryption domain for a route-based VPN is 0.0.0.0/0.&lt;BR /&gt;Routing to the VTI interfaces determine what is encrypted.&lt;BR /&gt;This isn't any different in R80.40</description>
      <pubDate>Wed, 22 Apr 2020 05:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82714#M11388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-22T05:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82722#M11389</link>
      <description>&lt;P&gt;Hi Phoneboy,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Only one of the vpns is a VTI.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other VPN is a normal domain based VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As mentioned customer wants to route via the check point "hub" from the one to the other.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(obviously there are additional vpns that I don't want to break in the process)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 06:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82722#M11389</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2020-04-22T06:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82808#M11390</link>
      <description>Ok, that kind of makes sense.&lt;BR /&gt;Note that when you mix route-based VPNs and domain-based VPNs on the same gateway, the configuration for domain-based VPNs applies first.&lt;BR /&gt;Which means: your domain-based VPN configuration should not include anything covered by the route-based VPN configuration.&lt;BR /&gt;You might need to use IP Pool NAT here to ensure traffic is routed back and forth correctly in this instance.</description>
      <pubDate>Wed, 22 Apr 2020 17:14:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/82808#M11390</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-22T17:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/83526#M11391</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;This did work with the help of the R80.40 different Encryption domains for each community. (could not do it without this)&lt;/P&gt;&lt;P&gt;Also used the vpn_route.conf to allow the inter vpn routing on the Check Point Hub Gateway. (only for traffic to go into the Domain based VPN - the VTI just worked with routing.)&lt;/P&gt;&lt;P&gt;No nat necessary but obviously the correct routing was required on both the 3rd party VTI VPN side and the 3rd party Domain based side.&lt;/P&gt;&lt;P&gt;Very impressed this worked:-) Love R80.40 now!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First time I have ever seen the VPN routing Icon --great stuff!!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 18:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/83526#M11391</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2020-04-28T18:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116627#M16447</link>
      <description>&lt;P&gt;Hi, i have the same issue with&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;vpn_route.conf&lt;/SPAN&gt;. How do you put&amp;nbsp;&lt;SPAN&gt;Interoperable Device in your&amp;nbsp;vpn_route.conf ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 12:48:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116627#M16447</guid>
      <dc:creator>Ara_Zohrabian</dc:creator>
      <dc:date>2021-04-22T12:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116658#M16454</link>
      <description>&lt;P&gt;Hi Ara_Zohrabian,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The format I used was&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;Remote_Encryption_Domain_subnet&amp;gt; &amp;lt;Remote_vpn_peer&amp;gt; &amp;lt;Local-Gateway&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All the names are as per the objects names in the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 15:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116658#M16454</guid>
      <dc:creator>Darren_Fine</dc:creator>
      <dc:date>2021-04-22T15:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116729#M16474</link>
      <description>&lt;P&gt;Hi, to be able to reach&amp;nbsp;10.200.0.0/19 (SiteC) from&amp;nbsp;10.0.0.0/13 (SiteA), you must add 10.0.0.0/13 in the HubCPgateway&amp;nbsp;encryption domain to SiteC. But i am always receiving the error "according to policy packet should not have been decrypted" because 10.0.0.0/13 &amp;nbsp;cannot be in both VPN (route base VPN and the domain base VPN). Do you have an idea?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 13:56:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116729#M16474</guid>
      <dc:creator>Ara_Zohrabian</dc:creator>
      <dc:date>2021-04-23T13:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between 3rd party A VTI VPN --&gt; CP --&gt; 3rd Party Domain based VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116736#M16476</link>
      <description>&lt;P&gt;You can't have overlapping encryption domains regardless of whether it's domain or route-based VPNs.&lt;BR /&gt;That can only be resolved by renumbering or NAT.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 17:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-3rd-party-A-VTI-VPN-gt-CP-gt-3rd-Party/m-p/116736#M16476</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-23T17:35:50Z</dc:date>
    </item>
  </channel>
</rss>

