<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to Site VPN HTTPS External Interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66185#M12244</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an existing clusterA with 2 gateways and a SMS server.&amp;nbsp; Cluster A has several internal interfaces, an external interface and a sync.&amp;nbsp; I have a new external clusterB that I have successfully added to my SMS.&amp;nbsp; The external clusterB has 2 internal interfaces, 1 external interface and a sync interface.&lt;/P&gt;&lt;P&gt;From the internal interface of clusterA to the external interface of new clusterB, I was able to SSH, HTTPS and ping.&amp;nbsp; After setting up a site to site VPN between clusterA and clusterB, I can no longer SSH or HTTPS from the internal interface of clusterA to the external interface of clusterB, but I can still ping from the internal interface of clusterA to the external interface of clusterB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can SSH/HTTPS from the internal interface of clusterA to the internal interfaces of cluster B.&lt;/P&gt;&lt;P&gt;On my other site to site VPNs (which I don't manage with my SMS), I see SSH being accepted on an implied rule, but on my new cluster, SSH just drops to the cleanup rule.&lt;/P&gt;&lt;P&gt;Any ideas on what the issue is?&amp;nbsp; Why I can no longer SSH/HTTPS from internal interface of clusterA to the external interface of clusterB?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 29 Oct 2019 20:27:18 GMT</pubDate>
    <dc:creator>KWD</dc:creator>
    <dc:date>2019-10-29T20:27:18Z</dc:date>
    <item>
      <title>Site to Site VPN HTTPS External Interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66185#M12244</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an existing clusterA with 2 gateways and a SMS server.&amp;nbsp; Cluster A has several internal interfaces, an external interface and a sync.&amp;nbsp; I have a new external clusterB that I have successfully added to my SMS.&amp;nbsp; The external clusterB has 2 internal interfaces, 1 external interface and a sync interface.&lt;/P&gt;&lt;P&gt;From the internal interface of clusterA to the external interface of new clusterB, I was able to SSH, HTTPS and ping.&amp;nbsp; After setting up a site to site VPN between clusterA and clusterB, I can no longer SSH or HTTPS from the internal interface of clusterA to the external interface of clusterB, but I can still ping from the internal interface of clusterA to the external interface of clusterB.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can SSH/HTTPS from the internal interface of clusterA to the internal interfaces of cluster B.&lt;/P&gt;&lt;P&gt;On my other site to site VPNs (which I don't manage with my SMS), I see SSH being accepted on an implied rule, but on my new cluster, SSH just drops to the cleanup rule.&lt;/P&gt;&lt;P&gt;Any ideas on what the issue is?&amp;nbsp; Why I can no longer SSH/HTTPS from internal interface of clusterA to the external interface of clusterB?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2019 20:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66185#M12244</guid>
      <dc:creator>KWD</dc:creator>
      <dc:date>2019-10-29T20:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN HTTPS External Interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66407#M12245</link>
      <description>Have you done a tcpdump/fw monitor on both ends to very the traffic is getting there?&lt;BR /&gt;What does it look like?&lt;BR /&gt;Also, what errors do you see in the logs?</description>
      <pubDate>Fri, 01 Nov 2019 20:09:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66407#M12245</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-01T20:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN HTTPS External Interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66526#M12246</link>
      <description>I was able to resolve the issue. But I appreciate your reply.</description>
      <pubDate>Mon, 04 Nov 2019 17:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66526#M12246</guid>
      <dc:creator>KWD</dc:creator>
      <dc:date>2019-11-04T17:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN HTTPS External Interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66587#M12247</link>
      <description>What was the issue?</description>
      <pubDate>Tue, 05 Nov 2019 12:29:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-HTTPS-External-Interface/m-p/66587#M12247</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-05T12:29:02Z</dc:date>
    </item>
  </channel>
</rss>

