<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuration for VPN to send 80/443 traffic to Netskope in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109316#M24865</link>
    <description>&lt;P&gt;I have a need to create VPN tunnels from a R80.40 gateway to Netskope cloud gateway.&amp;nbsp; Want to only send traffic from select internal source IP's that need internet bound http/https traffic to the Netskope cloud for inspection by their SWG.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone figure out how to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 22:18:23 GMT</pubDate>
    <dc:creator>Anthony_Vita</dc:creator>
    <dc:date>2021-01-29T22:18:23Z</dc:date>
    <item>
      <title>Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109316#M24865</link>
      <description>&lt;P&gt;I have a need to create VPN tunnels from a R80.40 gateway to Netskope cloud gateway.&amp;nbsp; Want to only send traffic from select internal source IP's that need internet bound http/https traffic to the Netskope cloud for inspection by their SWG.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone figure out how to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 22:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109316#M24865</guid>
      <dc:creator>Anthony_Vita</dc:creator>
      <dc:date>2021-01-29T22:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109326#M24866</link>
      <description>&lt;P&gt;You can certainly create an encryption domain with the specific hosts in question and only those hosts.&lt;BR /&gt;However, it will potentially send all Internet-bound traffic from those hosts over the VPN, not just traffic on port 80/443.&lt;BR /&gt;Unless, of course, you deny all other traffic from those hosts to the Internet.&lt;/P&gt;
&lt;P&gt;Whether you can make this work with Netskope is a separate question.&lt;BR /&gt;Also, if the Check Point gateway can perform the same functions (which it likely can), why send the traffic there at all?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 06:39:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109326#M24866</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-30T06:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109336#M24867</link>
      <description>&lt;P&gt;Netscope performs combined functions of SWG, CASB and DLP that are a lot more granular than the CP gateway by itself can perform, so I can see a use case for this.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jan 2021 14:20:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109336#M24867</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-01-30T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109449#M24868</link>
      <description>&lt;P&gt;Correct, the additional functions that Netskope performs are part of the reason, another is a unified policy management point for all clients as our endpoints are using Netskope when off net.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;The need for sending only select hosts through the tunnel is for initial testing, eventually we will look to forward all clients that do not have a Netskope client installed (think servers, IOT) through this tunnel to the Netskope SWG.&amp;nbsp; I was trying to use VTI and PBR, to select the traffic.&amp;nbsp; I have the VPN community created and the Tunnel are up, but I can't get the traffic to pass.&amp;nbsp; I have a Rule at the top of the policy to match the source IP of the test clients destined to a Negated RFC1918 network group with a Directional match on the VPN and service of 80/443.&amp;nbsp; There is also a rule in the application policy for the same.&lt;/P&gt;&lt;P&gt;Looking at the logs, it shows the traffic being encrypted and moved to the appropriate Tunnel interface, but matched on a lower rule for all other Internet bound traffic, not the Directional match rule at the top.&amp;nbsp; Then there is an accept that is not encrypted, with the message:&amp;nbsp; Connection terminated before detection: Insufficient data passed.&amp;nbsp; See SK113479.&amp;nbsp; What am I missing?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109449#M24868</guid>
      <dc:creator>Anthony_Vita</dc:creator>
      <dc:date>2021-02-01T14:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109451#M24869</link>
      <description>&lt;P&gt;I'm not familiar with NetScope Cloud Gateway requirements, but am curious why the use of VTIs and PBR is required.&lt;/P&gt;
&lt;P&gt;Depending on what version of Check Point you are on, I think the use of custom local VPN Domain with VPN Community is a better way of sending traffic from select hosts or access roles to NetScope, if they support domain-based VPNs.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109451#M24869</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-02-01T14:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109455#M24870</link>
      <description>&lt;P&gt;Hi Anthony,&lt;/P&gt;&lt;P&gt;Sometime ago I made a configuration look you are need, I can remember that a VPN universal tunnel was configured for this.&lt;/P&gt;&lt;P&gt;Basically we used policy based VPN instead of route based (VTI), with "&lt;SPAN&gt;Route All Traffic Through This Site" enabled on VPN community to negociate&amp;nbsp;0.0.0.0-0.0.0.0 with remote peer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The biggest challenge to do this configuration is because you're forwarding all traffic through this tunnel. Thus, now PBR policies can be helpful to redesign outgoing paths.&lt;BR /&gt;&lt;BR /&gt;In my case I routed all traffic, wasn't necessary be a previous test before production, because were a new enviroment.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I hope that my short words can help you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Alisson Lima&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/109455#M24870</guid>
      <dc:creator>firewall1-gx</dc:creator>
      <dc:date>2021-02-01T14:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/151617#M24871</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;did you solve the problem? Same situation here, RouteBased+PBR but i get "Failed to enforce VPN Policy (11)"&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 14:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/151617#M24871</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-23T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/151647#M24892</link>
      <description>&lt;P&gt;I did not solve this problem and ended up using a different device to terminate the tunnels for my testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 17:08:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/151647#M24892</guid>
      <dc:creator>Anthony_Vita</dc:creator>
      <dc:date>2022-06-23T17:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/197480#M36890</link>
      <description>&lt;P&gt;I think thats a good fix.&lt;/P&gt;&lt;P&gt;I was looking at pbr and route based vpn with unnumbered vti but its a bit odd with a cluster, although I think this would be the nicest solution.&lt;/P&gt;&lt;P&gt;I did however just find this - so there is a solution using some tricks from 2022 with groups with exclusions/excluded services and mep it seems;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179920" target="_blank"&gt;Configuring Site-to-Site VPN between a Check Point Gateway and Netskope&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 16:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/197480#M36890</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2023-11-08T16:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/228569#M43960</link>
      <description>&lt;P&gt;Hi, was somebody able to configure this VPN with netskope following the article above (&lt;SPAN&gt;sk179920)? I have followed it but the other side is always returning "gateway to gateway authentication error", I suppose it was the usual problem with the ID and 3rd party VPNs, but I have checked that the ID is right, is the same as the public IP address...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 09:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/228569#M43960</guid>
      <dc:creator>Diego_dg</dc:creator>
      <dc:date>2024-10-01T09:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/232576#M44912</link>
      <description>&lt;P&gt;I have seen that a customer with a large environment had used it successfully - lot of work though...&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 14:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/232576#M44912</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2024-11-13T14:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Configuration for VPN to send 80/443 traffic to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/232580#M44915</link>
      <description>&lt;P&gt;Thanks! we were able to make it work (in a POC), we had to adjust the encryption domain until the vpn was rightly established but in the end it worked&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 14:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuration-for-VPN-to-send-80-443-traffic-to-Netskope/m-p/232580#M44915</guid>
      <dc:creator>Diego_dg</dc:creator>
      <dc:date>2024-11-13T14:17:42Z</dc:date>
    </item>
  </channel>
</rss>

