<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Tunnel Management per Gateway Pair and consequences when I have multiple other tunnels in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58086#M12621</link>
    <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;I have total around 12 VPN Tunnels running on 5900; all are Policy/Domains based VPN. I have been asked to move and see the possibiities one Tunnel out of those 12 to One VPN tunnel per Gateway Pair.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering what could be the consequences on other tunnels then? Since I know One VPN tunnel per Gateway pair means CP will start sending/accepting 0.0.0.0/0.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Blason R&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2019 08:31:16 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2019-07-12T08:31:16Z</dc:date>
    <item>
      <title>VPN Tunnel Management per Gateway Pair and consequences when I have multiple other tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58086#M12621</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;I have total around 12 VPN Tunnels running on 5900; all are Policy/Domains based VPN. I have been asked to move and see the possibiities one Tunnel out of those 12 to One VPN tunnel per Gateway Pair.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering what could be the consequences on other tunnels then? Since I know One VPN tunnel per Gateway pair means CP will start sending/accepting 0.0.0.0/0.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Blason R&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 08:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58086#M12621</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2019-07-12T08:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnel Management per Gateway Pair and consequences when I have multiple other tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58087#M12622</link>
      <description>&lt;P&gt;Where did you learn that 0.0.0.0 thing ? According to&amp;nbsp;Site to Site VPN Administration Guide R80.30 p.94&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;VPN Tunnel Sharing provides greater interoperability and scalability by controlling the number of VPN tunnels created between peer Security Gateways. Configuration of VPN Tunnel Sharing can be set on both the VPN community and Security Gateway object.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;• &lt;STRONG&gt;One VPN Tunnel per each pair of hosts &lt;/STRONG&gt;- A VPN tunnel is created for every session initiated between every pair of hosts.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;• &lt;STRONG&gt;One VPN Tunnel per subnet pair&lt;/STRONG&gt;- Once a VPN tunnel has been opened between two subnets, subsequent sessions between the same subnets will share the same VPN tunnel. This is the default setting and is compliant with the IPsec industry standard.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;• &lt;STRONG&gt;One VPN Tunnel per Security Gateway pair &lt;/STRONG&gt;- One VPN tunnel is created between peer Security Gateways and shared by all hosts behind each peer Security Gateway.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 08:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58087#M12622</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-12T08:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnel Management per Gateway Pair and consequences when I have multiple other tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58089#M12623</link>
      <description>&lt;P&gt;Surprising!! I last time done the debug and vpnd.elg was showing 0.0.0.0/0 and setting was One VPN Tunnel Per Gateway pair.&amp;nbsp; I guess even&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;has suggested it to move to per subnet pair and it resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 08:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58089#M12623</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2019-07-12T08:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Tunnel Management per Gateway Pair and consequences when I have multiple other tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58090#M12624</link>
      <description>&lt;P&gt;So in that case it should not be an issue moving to that setting for one tunnel, right?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 08:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Tunnel-Management-per-Gateway-Pair-and-consequences-when-I/m-p/58090#M12624</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2019-07-12T08:53:44Z</dc:date>
    </item>
  </channel>
</rss>

