<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Interoperable object with same IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159547#M27951</link>
    <description>&lt;P&gt;I personally had never seen this done with any vendor before...would love an example of it working.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 13:00:32 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-10-14T13:00:32Z</dc:date>
    <item>
      <title>VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159520#M27932</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;A quick question, is it possible to have a interoperable object using the same IP? We want to build VPNs to a third party firewall but some different policies / vpn domains behind the same object need to be used.&lt;/P&gt;&lt;P&gt;We have tried this and it seems to have caused some issues, even though the different object is used in different communities.&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 08:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159520#M27932</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T08:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159522#M27933</link>
      <description>&lt;P&gt;Using the same IP as what else is using ? How to do routing in this situation ?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 08:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159522#M27933</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-14T08:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159523#M27937</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The interoperable object is a Cisco ASA FW, we build VPNs to it from our Checkpoint Firewalls.&lt;/P&gt;&lt;P&gt;I have created another object using a different name but the same IP, this is then used in different vpn communities&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 09:16:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159523#M27937</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T09:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159526#M27939</link>
      <description>&lt;P&gt;&lt;SPAN&gt;So how do you expect VPN routing will work in this situation with two identical IPs ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 09:36:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159526#M27939</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-14T09:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159527#M27940</link>
      <description>&lt;P&gt;its from 2 different Checkpoints using 2 different vpn communities and 2 different "named" objects. every other firewall vendor has no issue doing this.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 09:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159527#M27940</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T09:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159528#M27941</link>
      <description>&lt;P&gt;Can you provide a topology map? These are 2 different CP GWs and the double IP is not present on one GW, but each has the same IP ?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 10:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159528#M27941</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-14T10:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159530#M27943</link>
      <description>&lt;P&gt;Hi, see attached diagram, I have made up the IP's for ref only&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 10:49:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159530#M27943</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T10:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159533#M27944</link>
      <description>&lt;P&gt;And both CP GWs are managed by the same SMS ? Better open a SR# with CP TAC to get to a supported configuration !&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 11:25:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159533#M27944</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-14T11:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159546#M27950</link>
      <description>&lt;P&gt;I recommend checking with TAC if this is a supported configuration (having two different VPN gateways with same IP).&lt;BR /&gt;Pretty sure this won’t work/be supported, though.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 12:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159546#M27950</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T12:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159547#M27951</link>
      <description>&lt;P&gt;I personally had never seen this done with any vendor before...would love an example of it working.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 13:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159547#M27951</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-14T13:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159551#M27954</link>
      <description>&lt;P&gt;If its not supported, that means every Checkpoint Gateway is forced to use the same parameters and vpn domains as all the others, this is not flexible at all if this is the case.&lt;/P&gt;&lt;P&gt;With ASA and other vendors you can choose whatever subnets you like to different firewalls using different polices etc&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 13:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159551#M27954</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2022-10-14T13:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159552#M27955</link>
      <description>&lt;P&gt;With CP, you can always choose different VPN domain for different VPN communities, thats been supported for some time now. Now, obviously, you create separate rules (usually within same policy package) to reflect access needed for each VPN community.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are we missing something here?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 13:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159552#M27955</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-14T13:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159553#M27956</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Always that i have faced a situation with duplicated IP addresses TAC told me to avoid that. Many features look for the specific object into the data base using the IP address and it can end using the wrong object.&lt;/P&gt;
&lt;P&gt;I think it is possible to get this working, but never had this scenario. I would try adding both remote vpn domains in one interoperable object, lets's say remote vpn domain A and remote vpn domain B. And make sure tunnel sharing is set to "per subnet pair".&lt;/P&gt;
&lt;P&gt;Just make sure that on the first checkpoint gateway, the generated traffic is always with destination remote vpn domain A, so in phase two, checkpoint gateway will send the ID's --&amp;gt; "Your_Network - remote vpn domain A", and only that, it will not include remote network B, the ID's are based on the generated traffic. And the same on second checkpoint gateway, only traffic with destination remote vpn domain B should go through this gateway.&lt;/P&gt;
&lt;P&gt;Of course you have to manage your internal routing correctly for both remote vpn domains, if these are adjacent networks maybe you will have to edit user.def file to avoid supernetting, take care of NAT, etc, etc. Again it is my personal opinion and never configured something like your scenario. HTH.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 13:13:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159553#M27956</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-10-14T13:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable object with same IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159554#M27957</link>
      <description>&lt;P&gt;Forgot the other option that would avoid vpn domain's issues, you can use route based vpn's!!! and keep yourself on a supported configuration as G_W_Albrecht said in case you need TAC assistance.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 13:22:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-object-with-same-IP/m-p/159554#M27957</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-10-14T13:22:31Z</dc:date>
    </item>
  </channel>
</rss>

