<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN peer in multiple VPN Communities in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158563#M27656</link>
    <description>&lt;P&gt;Yes, it does make sense, but please make sure you figure out routing in the process. I would start in a lab first&lt;/P&gt;</description>
    <pubDate>Sat, 01 Oct 2022 09:14:52 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-10-01T09:14:52Z</dc:date>
    <item>
      <title>VPN peer in multiple VPN Communities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158550#M27655</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using R81.10 with a number of domain-based S2S VPNs but am starting to get a number of requests for route-based VPNs. Normally that's fine for new peers but I have one request to switch a VPN from domain-based to route-based and am wanting to know if I can make roll-back easy by not having to dismantle any of the existing VPN.&lt;/P&gt;&lt;P&gt;So, here's the situation.&lt;/P&gt;&lt;P&gt;I have an existing interoperable device, call it vpn_ABC that is used as a satellite gateway in a domain-based community, call it Domain_Community.&lt;/P&gt;&lt;P&gt;The peer's owner wants to switch to route-based VPN but using the same peer (vpn_ABC).&lt;/P&gt;&lt;P&gt;If I create a new community, say Routed_Community, can I use the same centre gateway and same satellite gateway in that community but manually change the VPN domains for those gateways within this new community to be an empty group which I have created for route-based VPNs. In other words I'd end up with this:&lt;/P&gt;&lt;P&gt;Domain_Community (not used in any rules)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;centre gateway = my_cluster with VPN domain = VPN_Domain (object group with multiple networks)&lt;/LI&gt;&lt;LI&gt;satellite gateway = vpn_ABC with VPN domain = ABC_Domain (object group with multiple networks)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Routed_Community (used in a rule)&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;centre gateway = my_cluster with VPN domain, manually set in the community = Empty_Group&lt;/LI&gt;&lt;LI&gt;satellite gateway = vpn_ABC with VPN domain, manually set in the community = Empty_Group&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Will such a setup even work? Will my_cluster know to use the route-based VPN instead of the domain-based VPN?&lt;/P&gt;&lt;P&gt;Does any of that make sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 22:26:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158550#M27655</guid>
      <dc:creator>Colin_Campbell1</dc:creator>
      <dc:date>2022-09-30T22:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN peer in multiple VPN Communities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158563#M27656</link>
      <description>&lt;P&gt;Yes, it does make sense, but please make sure you figure out routing in the process. I would start in a lab first&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 09:14:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158563#M27656</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-01T09:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN peer in multiple VPN Communities</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158860#M27756</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Got the answer this morning when I installed policy which failed verification: "Please note that a pair of objects can appear only in one intranet community at most."&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Wed, 05 Oct 2022 21:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-peer-in-multiple-VPN-Communities/m-p/158860#M27756</guid>
      <dc:creator>Colin_Campbell1</dc:creator>
      <dc:date>2022-10-05T21:43:41Z</dc:date>
    </item>
  </channel>
</rss>

