<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote VPN access to network behind 3rd party Gateway  in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16390#M1213</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A visual network diagram would be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Dec 2018 14:30:44 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-14T14:30:44Z</dc:date>
    <item>
      <title>Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16389#M1212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come upon this issue where a customer is trying to access a Network scope behind a tunnel that is terminating on a 3rd party device.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the topology is the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client VPN client with remote office IP 10.1.1.2 want´s to reach Server Behind Tunnel Terminating on 3rd party firewall with IP 192.168.2.2&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint has route for 192.168.2.0/24 -&amp;gt; 3rd party device&amp;nbsp;&lt;/P&gt;&lt;P&gt;3rd Party device has route to 10.1.1.0/24 -&amp;gt; checkpoint&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network 192.168.2.0/24 is part of Enc Domain of Checkpoint for Remote VPN&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem is when the client tries to reach network packet is forwarded to server, return packet however is blocked by checkpoint with following error:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dropped by vpn_verify, reason : Clear packet on encrypted connection;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don´t understand the drop because the packet should be Clear text and only be encrypted by the checkpoint and decrypted by the client, I don´t see the difference between this and any other network access, I wondering if It has to do with the Topology since this network is not directly connected, however there is a route so it should be "known" in terms of topology.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this I tried adding the Remote Office Pool to the Enc. Domain of the Gateway, however this simply changed the error output to:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;No Decryption Message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the second error is because now the Gateway thinks it needs to Decrypt and it´s clear text or something..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 13:39:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16389#M1212</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-12-14T13:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16390#M1213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A visual network diagram would be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 14:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16390#M1213</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-14T14:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16391#M1214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic is initiated on Remote VPN side:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I can see in FW monitor the traffic being send to destination network and I can also see on 3rd party the traffic being send to server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The return traffic hits the 3rd party device and get´s blocked on checkpoint side with described errors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76394_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 14:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16391#M1214</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-12-14T14:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16392#M1215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like the remote end is not encrypting the reply traffic for some reason.&lt;/P&gt;&lt;P&gt;Can you confirm it is received cleartext on the Check Point?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 16:31:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16392#M1215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-14T16:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16393#M1216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should not encrypt the reply, the reply is&amp;nbsp;decrypted on 3rd party firewall correctly, send as clear text to Checkpoint and should then be encrypted to be sent to the Remote VPN tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original packet is Encrypted on Client Side, decrypted on Checkpoint side and send as Clear text to 3rd party device, then encrypted and send to server (server sits behind some other device this I don´t know).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a tunnel Between 3rd Party and some other gateway and destination network is behind this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the traffic flow between Checkpoint and 3rd party is always unencrypted.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 16:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16393#M1216</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-12-14T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16394#M1217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you done any of the steps in this SK?&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93204" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93204"&gt;Troubleshooting "Clear text packet should be encrypted" error in ClusterXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 18:50:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16394#M1217</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-14T18:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16395#M1218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any specific section in mind by referring this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2018 08:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16395#M1218</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2018-12-17T08:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16396#M1219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, now that I look at it a bit more closely, probably not &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Do you have a TAC case on this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2018 14:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16396#M1219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-17T14:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPN access to network behind 3rd party Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16397#M1220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ricardo,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you know if this scenario is&amp;nbsp;supported or working,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to do something similar but I am not sure it is supported.&lt;/P&gt;&lt;P&gt;I want to know if you approached TAC before I start to configure and test it&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2019 06:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPN-access-to-network-behind-3rd-party-Gateway/m-p/16397#M1220</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2019-02-15T06:46:54Z</dc:date>
    </item>
  </channel>
</rss>

