<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN between Checkpoint cluster and Zscaler ZIA public service edge as documented in sk174848 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175755#M32091</link>
    <description>&lt;P&gt;We are trying to implement a VPN tunnel between our Checkpoint 7000 cluster and the Zscaler ZIA service as documented in sk174848.&amp;nbsp; It looks like this procedure will cause ALL traffic, including traffic that would normally be handled by other VPN tunnels on the same cluster, traffic that would normally be routed to DMZ segments on the cluster, traffic from the Checkpoints to Checkpoint cloud update services and other traffic that should bypass the tunnel and go direct to the Internet, to be sent through this Zscaler tunnel.&amp;nbsp; How can one exclude this traffic from going into the Zscaler tunnel?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Mar 2023 13:49:14 GMT</pubDate>
    <dc:creator>Christine_Berns</dc:creator>
    <dc:date>2023-03-22T13:49:14Z</dc:date>
    <item>
      <title>VPN between Checkpoint cluster and Zscaler ZIA public service edge as documented in sk174848</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175755#M32091</link>
      <description>&lt;P&gt;We are trying to implement a VPN tunnel between our Checkpoint 7000 cluster and the Zscaler ZIA service as documented in sk174848.&amp;nbsp; It looks like this procedure will cause ALL traffic, including traffic that would normally be handled by other VPN tunnels on the same cluster, traffic that would normally be routed to DMZ segments on the cluster, traffic from the Checkpoints to Checkpoint cloud update services and other traffic that should bypass the tunnel and go direct to the Internet, to be sent through this Zscaler tunnel.&amp;nbsp; How can one exclude this traffic from going into the Zscaler tunnel?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 13:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175755#M32091</guid>
      <dc:creator>Christine_Berns</dc:creator>
      <dc:date>2023-03-22T13:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between Checkpoint cluster and Zscaler ZIA public service edge as documented in sk174848</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175826#M32110</link>
      <description>&lt;P&gt;I believe, in this case, only traffic routed to the default route is sent across the tunnel.&lt;BR /&gt;Which means any more specific routes should apply first (i.e. for your LAN/DMZ or similar).&lt;BR /&gt;As for excluding traffic from Check Point updates, etc: my first thought was to see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167135" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167135&lt;/A&gt;&lt;BR /&gt;Unfortunately, this isn’t supported with VPN.&lt;/P&gt;
&lt;P&gt;Which means: what you’re asking for is very likely an RFE.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 20:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175826#M32110</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-22T20:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between Checkpoint cluster and Zscaler ZIA public service edge as documented in sk174848</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175834#M32111</link>
      <description>&lt;P&gt;Our VPNs are configured as domain-based VPNs.&amp;nbsp; Let's say a packet for an external site gets routed via the default route to the firewall external interface and there are two VPN communities that this packet matches.&amp;nbsp; Community-A is for a specific VPN to a client and the packet matches the specific source and destination addresses defined in the source and destination encryption domains.&amp;nbsp; &amp;nbsp;Community-B is for this Zscaler VPN and the packet matches the specific source address in the source encryption domain and also matches on the destination as this VPN is configured as a universal tunnel (as required by Zscaler).&amp;nbsp; Which VPN community will this packet be encrypted by?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 21:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175834#M32111</guid>
      <dc:creator>Christine_Berns</dc:creator>
      <dc:date>2023-03-22T21:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between Checkpoint cluster and Zscaler ZIA public service edge as documented in sk174848</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175909#M32130</link>
      <description>&lt;P&gt;When you use an empty encryption domain, it’s a route-based VPN.&lt;BR /&gt;In this case, the following rules apply:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;BR /&gt;Bottom line: Domain-Based VPNs take precidence.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 13:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-Checkpoint-cluster-and-Zscaler-ZIA-public-service/m-p/175909#M32130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-23T13:57:06Z</dc:date>
    </item>
  </channel>
</rss>

