<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encryption Domain with Exclusion Group in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74372#M11615</link>
    <description>&lt;P&gt;Yes. I configured the exclusion group as encryption domain.&lt;/P&gt;&lt;P&gt;Even worked excluding the external IP of remote gateway, so this way, was not included on encryption domain automatically.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 19:43:53 GMT</pubDate>
    <dc:creator>KennyManrique</dc:creator>
    <dc:date>2020-02-06T19:43:53Z</dc:date>
    <item>
      <title>Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74348#M11612</link>
      <description>&lt;P&gt;Is it possible to use an exclusion group as part of a VPN encryption domain? Or do I have to list out all the network objects that I want and not include the ones I don't want?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 15:17:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74348#M11612</guid>
      <dc:creator>Evan_Fisher</dc:creator>
      <dc:date>2020-02-06T15:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74354#M11613</link>
      <description>&lt;P&gt;I did for one customer whose internal subnet had another devices reachable without VPN (Switches and Routers). On my case, excluding only the hosts (ex. Remote Domain Net 192.168.1.0/24, excluding 192.168.1.2 and 192.168.1.3) It worked without issues.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74354#M11613</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2020-02-06T16:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74355#M11614</link>
      <description>&lt;P&gt;And you used an exclusion group? Object Explorer -&amp;gt; Network Objects -&amp;gt; Groups -&amp;gt; Group with Exclusions ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:14:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74355#M11614</guid>
      <dc:creator>Evan_Fisher</dc:creator>
      <dc:date>2020-02-06T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74372#M11615</link>
      <description>&lt;P&gt;Yes. I configured the exclusion group as encryption domain.&lt;/P&gt;&lt;P&gt;Even worked excluding the external IP of remote gateway, so this way, was not included on encryption domain automatically.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 19:43:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74372#M11615</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2020-02-06T19:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74374#M11616</link>
      <description>&lt;P&gt;Evan,&lt;/P&gt;
&lt;P&gt;as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5874"&gt;@KennyManrique&lt;/a&gt;&amp;nbsp; mentioned, it is no problem to use a group with exclusions as encryption domain.&lt;/P&gt;
&lt;P&gt;I think 80% of our customers are doing this.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 20:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74374#M11616</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-02-06T20:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74385#M11617</link>
      <description>We did use it also, but found some weird behavior with it, it stopped working based on Network to Network and started working with host based tunnels instead.&lt;BR /&gt;Must say this was with R77.30 gateways.</description>
      <pubDate>Thu, 06 Feb 2020 21:51:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74385#M11617</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-06T21:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74554#M11618</link>
      <description>&lt;P&gt;Yes, depending on the size of the excluded hosts/networks it may cause a change in behavior for the size of the subnets proposed in IKE Phase 2, particularly when hosts (/32) are excluded.&amp;nbsp; When exclusions are used, the VPN domain is recalculated into multiple networks/subnets to exclude the desired addresses.&amp;nbsp; You can use tools like Danny Jung's VPN Domain One-liner to see this in action:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-to-show-VPN-topology-on-gateways/m-p/57975" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-to-show-VPN-topology-on-gateways/m-p/57975&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 15:53:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74554#M11618</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-09T15:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74561#M11619</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Groups with exclusions have many limitations one should be aware of. (&lt;/SPAN&gt;&lt;EM&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk97246" rel="nofollow noopener noreferrer" target="_blank"&gt;sk97246&lt;/A&gt;, &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk101506" rel="nofollow noopener noreferrer" target="_blank"&gt;sk101506&lt;/A&gt;, &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk107543" rel="nofollow noopener noreferrer" target="_blank"&gt;sk107543&lt;/A&gt;, &lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk107417" rel="nofollow noopener noreferrer" target="_blank"&gt;sk107417&lt;/A&gt;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;, ..&lt;/EM&gt;)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've also mentioned this in my article about&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Policy-Management/Properly-defining-the-Internet-within-a-security-policy/td-p/10561" target="_self"&gt;Properly defining the Internet within a security policy&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 16:33:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/74561#M11619</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-02-09T16:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/133557#M19865</link>
      <description>&lt;P&gt;How did you exactly do it ?&lt;/P&gt;&lt;P&gt;You defined the public ip of the gateway as a host object, then included the host object inside a network group object and then excluded it in the excluded section of a network group with exclusions object ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 22:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/133557#M19865</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-11-08T22:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption Domain with Exclusion Group</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/185275#M34067</link>
      <description>&lt;P&gt;Hello Dany,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;the most important thing when working with Encryption Domains and Exclusions is this SK&amp;nbsp;sk39679&lt;BR /&gt;&lt;BR /&gt;you have to switch to &lt;STRONG&gt;"one tunnel per gateway pair"&lt;/STRONG&gt; as this SK&amp;nbsp;sk39679 states&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 08:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-Domain-with-Exclusion-Group/m-p/185275#M34067</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2023-06-30T08:19:32Z</dc:date>
    </item>
  </channel>
</rss>

