<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain Based VPN Domain Routing Questions in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/110998#M15286</link>
    <description>&lt;P&gt;“&lt;SPAN&gt;accept all encrypted traffic” shouldn’t break VPN tunnels and you will need to add the relevant AWS subset to the encryption domain of the relevant gateway.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you edit the file incorrectly and push to the gateways, there is a risk it could be disruptive.&lt;BR /&gt;You might want to do it during a maintenance window.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 06:13:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-02-17T06:13:14Z</dc:date>
    <item>
      <title>Domain Based VPN Domain Routing Questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/110935#M15285</link>
      <description>&lt;P&gt;Hi everyone. I'm trying to setup routing from a branch office to AWS via another office. I've read up on Domain Based VPN and I have some questions about it. All of our gateways are in a meshed community. On the CP article it mentions that the 'accept all encrypted traffic' box should be set within the community settings (we have it unticked).&lt;/P&gt;&lt;P&gt;Is this going to break VPN tunnels between all of our offices if I do this? I understand that I need to edit the vpn_routing.conf file on the security management server and then install policy on the relevant gateway.&lt;/P&gt;&lt;P&gt;I have also read from other sources that the subnet in AWS will have to be added to the VPN domain of the gateway that the branch gateway forwards the traffic to/receives from. Is this correct?&lt;/P&gt;&lt;P&gt;Finally, if I only make the change to the conf file on the SMS, how likely is it that something will go wrong? I've not done this before so I don't want to bring everything crashing down!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 16:50:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/110935#M15285</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2021-02-16T16:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Based VPN Domain Routing Questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/110998#M15286</link>
      <description>&lt;P&gt;“&lt;SPAN&gt;accept all encrypted traffic” shouldn’t break VPN tunnels and you will need to add the relevant AWS subset to the encryption domain of the relevant gateway.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you edit the file incorrectly and push to the gateways, there is a risk it could be disruptive.&lt;BR /&gt;You might want to do it during a maintenance window.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 06:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/110998#M15286</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-17T06:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Based VPN Domain Routing Questions</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/112097#M15544</link>
      <description>&lt;P&gt;Thanks PhoneBoy. The change was made and, although traffic isn't successfully passing through yet, there aren't any major issues as a result of the change!&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 13:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Based-VPN-Domain-Routing-Questions/m-p/112097#M15544</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2021-03-01T13:35:02Z</dc:date>
    </item>
  </channel>
</rss>

