<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IKE IDs is smaller than Encryption Domain definition in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151778#M24963</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;very small setup:&lt;/P&gt;&lt;P&gt;S2S VPN Domain based, my enc domain has only 10.10.0.0/16,&lt;/P&gt;&lt;P&gt;Anyway, what i found by vpn tu is that my ike id is 10.10.0.0/17.&lt;/P&gt;&lt;P&gt;Trying to connect to a host inside 10.10.128.0/17, I get a new IKE id with a /32 on my side, this is related to the host IP of course.&lt;/P&gt;&lt;P&gt;I checked all my communities, but it seems that this behavior is not linked to&amp;nbsp;&lt;SPAN&gt;sk170857.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, why this happens?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe some NAT rule inside 10.10.128.0/17 is breaking the subnet because of the natted IP which is not in peer's enc domain?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks a lot&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Sat, 25 Jun 2022 10:59:47 GMT</pubDate>
    <dc:creator>CheckPointerXL</dc:creator>
    <dc:date>2022-06-25T10:59:47Z</dc:date>
    <item>
      <title>IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151778#M24963</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;very small setup:&lt;/P&gt;&lt;P&gt;S2S VPN Domain based, my enc domain has only 10.10.0.0/16,&lt;/P&gt;&lt;P&gt;Anyway, what i found by vpn tu is that my ike id is 10.10.0.0/17.&lt;/P&gt;&lt;P&gt;Trying to connect to a host inside 10.10.128.0/17, I get a new IKE id with a /32 on my side, this is related to the host IP of course.&lt;/P&gt;&lt;P&gt;I checked all my communities, but it seems that this behavior is not linked to&amp;nbsp;&lt;SPAN&gt;sk170857.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, why this happens?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe some NAT rule inside 10.10.128.0/17 is breaking the subnet because of the natted IP which is not in peer's enc domain?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks a lot&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 25 Jun 2022 10:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151778#M24963</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-25T10:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151779#M24964</link>
      <description>&lt;P&gt;Go to guidbedit and search for supernet, ike_use...cant remember exact values now, but may have to do with those.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 11:05:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151779#M24964</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-25T11:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151781#M24966</link>
      <description>&lt;P&gt;do you mean&amp;nbsp;&lt;SPAN&gt;ike_use_largest_possible_subnets ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It seems that i'm facing the opposite problem...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 11:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151781#M24966</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-25T11:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151782#M24967</link>
      <description>&lt;P&gt;Yes, that, but also any supernet setting, turn it to false.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 11:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151782#M24967</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-25T11:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151785#M24969</link>
      <description>&lt;P&gt;Check the VPN community settings to see if it is configured "per pair of hosts".&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 20:04:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151785#M24969</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-06-25T20:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: IKE IDs is smaller than Encryption Domain definition</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151788#M24971</link>
      <description>&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;Thank you for your feedback.&lt;/P&gt;&lt;P&gt;Of course is configured "per subnet pair", domain based setup.&lt;/P&gt;&lt;P&gt;Next hours i will check for previous mentioned dnguiedt value&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jun 2022 22:15:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IKE-IDs-is-smaller-than-Encryption-Domain-definition/m-p/151788#M24971</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2022-06-25T22:15:01Z</dc:date>
    </item>
  </channel>
</rss>

