<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: exclude gw public ip from encryption domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135303#M20373</link>
    <description>&lt;P&gt;Do i need to exclude HQs public IP from all the CPs ??&lt;/P&gt;&lt;P&gt;I was thinking that if i could exclude it from the HQs crypt.def would suffice&lt;/P&gt;</description>
    <pubDate>Tue, 30 Nov 2021 21:58:29 GMT</pubDate>
    <dc:creator>Nikolaos_Liakop</dc:creator>
    <dc:date>2021-11-30T21:58:29Z</dc:date>
    <item>
      <title>exclude gw public ip from encryption domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135194#M20357</link>
      <description>&lt;P&gt;We have a couple of remote branch offices which consist of 1500 series SMB (centrally or locally managed) and a Cluster of CP at our HQ.&lt;BR /&gt;All of the remote branch offices connect to the HQ via a Star Topology S2S VPN.&lt;/P&gt;&lt;P&gt;We want our remote branch office users to be able to connect via client vpn (capsule,ENS) towards the HQ besides the S2S VPN&lt;BR /&gt;which is something we cannot accomplish at the moment&lt;/P&gt;&lt;P&gt;I suppose we can't connect due to the fact that the HQs public IP belongs to the encryption domain which is something that i want to exclude.&lt;BR /&gt;I know also that this can be accomplished via crypt.def. but no matter how hard i tried i cannot do it.&lt;/P&gt;&lt;P&gt;Has anyone done something similar and wants to share a template or an excerpt from crypt.def so that I can see what am I doing wrong ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 22:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135194#M20357</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-11-29T22:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: exclude gw public ip from encryption domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135196#M20358</link>
      <description>&lt;P&gt;If you're just modifying $FWDIR/lib/crypt.def, that won't work for SMB gateways, which have their policy compiled from a different set of .def files.&lt;BR /&gt;More precisely they are in&amp;nbsp;/opt/CPSFWR80CMP-R81.10/lib (replace R81.10 with your management version).&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 22:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135196#M20358</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-29T22:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: exclude gw public ip from encryption domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135303#M20373</link>
      <description>&lt;P&gt;Do i need to exclude HQs public IP from all the CPs ??&lt;/P&gt;&lt;P&gt;I was thinking that if i could exclude it from the HQs crypt.def would suffice&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 21:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135303#M20373</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-11-30T21:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: exclude gw public ip from encryption domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135304#M20374</link>
      <description>&lt;P&gt;I think in your case, you'll have to exclude it in both places (the HQ gateways and the SMB gateway).&lt;BR /&gt;That means editing both .def files.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 22:04:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-gw-public-ip-from-encryption-domain/m-p/135304#M20374</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-30T22:04:46Z</dc:date>
    </item>
  </channel>
</rss>

