<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encryption domain - object types in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-domain-object-types/m-p/162828#M28983</link>
    <description>&lt;P&gt;IPSEC Tunnels are negotiated typically based on subnet, not host (though it's configurable).&lt;BR /&gt;That implies the use of network (not host) objects.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Nov 2022 17:31:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-11-22T17:31:49Z</dc:date>
    <item>
      <title>Encryption domain - object types</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-domain-object-types/m-p/162796#M28974</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm interested in Site to Site VPN local and remote encryption domain object types.&lt;/P&gt;&lt;P&gt;In some situations I have noticed that VPN Phase 2 doesn't work if I use in local and remote encryption domain objects type &lt;STRONG&gt;"host"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Lets assume:&lt;/P&gt;&lt;P&gt;Group_local_encryption_domain:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;10.255.1.0/24 (object type network)&lt;/LI&gt;&lt;LI&gt;192.168.10.5 (object type host)&lt;/LI&gt;&lt;LI&gt;10.1.1.10 (object type host)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If I change objects type &lt;STRONG&gt;"host" &lt;/STRONG&gt;to be &lt;STRONG&gt;"network" &lt;/STRONG&gt;objects with mask &lt;STRONG&gt;/32 &lt;/STRONG&gt;Phase 2 is up and everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group_local_encryption_domain:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;10.255.1.0/24 (object type network)&lt;/LI&gt;&lt;LI&gt;192.168.10.5/32 (object type network)&lt;/LI&gt;&lt;LI&gt;10.1.1.10/32 (object type network)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please, can someone confirm me that objects inside local or remote encryption domain must be type &lt;STRONG&gt;"network"&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 15:10:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-domain-object-types/m-p/162796#M28974</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2022-11-22T15:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Encryption domain - object types</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-domain-object-types/m-p/162828#M28983</link>
      <description>&lt;P&gt;IPSEC Tunnels are negotiated typically based on subnet, not host (though it's configurable).&lt;BR /&gt;That implies the use of network (not host) objects.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2022 17:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encryption-domain-object-types/m-p/162828#M28983</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-22T17:31:49Z</dc:date>
    </item>
  </channel>
</rss>

