<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176107#M32192</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27524"&gt;@carl_t&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a look at recent post and what I gave to fix it. Hates me to type it all now, so just open the link and its all there.&lt;/P&gt;
&lt;P&gt;If you have any questions, let me know, we can discuss further.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Site-to-site-Disconnects-amp-Questions/m-p/175758#M32093" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Site-to-site-Disconnects-amp-Questions/m-p/175758#M32093&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2023 15:06:08 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-03-24T15:06:08Z</dc:date>
    <item>
      <title>Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176106#M32191</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;We have created a VPN tunnel between a R81.10 gateway and a Cisco ASA, the setting is one vpn tunnel per subnet pair.&lt;/P&gt;&lt;P&gt;The subnet on the ASA side is&amp;nbsp; 172.16.0.0/12 to the Checkpoint which is 172.28.25.0/24&lt;/P&gt;&lt;P&gt;However when we look at the ASA and do a vpn tu tlist on the Checkpoint we see lots of random tunnels to different subnets within this 172.16.0.0/12 network, for example we see a tunnel formed to 172.24.0.0/14 and 172.16.0.0/13.&lt;/P&gt;&lt;P&gt;Where are these funny subnets being pulled from as none of these are set on the config, why are these showing?&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176106#M32191</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2023-03-24T15:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176107#M32192</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27524"&gt;@carl_t&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a look at recent post and what I gave to fix it. Hates me to type it all now, so just open the link and its all there.&lt;/P&gt;
&lt;P&gt;If you have any questions, let me know, we can discuss further.&lt;/P&gt;
&lt;P&gt;Cheers mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Site-to-site-Disconnects-amp-Questions/m-p/175758#M32093" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Site-to-site-Disconnects-amp-Questions/m-p/175758#M32093&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:06:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176107#M32192</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T15:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176109#M32194</link>
      <description>&lt;P&gt;Hi Andy&lt;/P&gt;&lt;P&gt;Thanks for your response, firstly we are not getting any drops just loads of random SA's&lt;/P&gt;&lt;P&gt;Where is it getting these funny supernets from? for example what makes the checkpoint pick&amp;nbsp;172.24.0.0/14 even though is is not configured in any vpn settings? or any objects configured on the gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:14:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176109#M32194</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2023-03-24T15:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176112#M32196</link>
      <description>&lt;P&gt;Its from those guidbedit settings I mentioned in the post. So, to make long story short, this had been the problem with Check Point, for I dont know, last 20 years : - )&lt;/P&gt;
&lt;P&gt;So, here is really basic example...lets pretend you want CP to advertise /29 to Cisco and thats what Cisco is expecting...fantastic. Now, you do your enc domains, verify everything, install policy and realize its failing on phase 2.&lt;/P&gt;
&lt;P&gt;Why you may wonder? Its because Cisco is EXPECTING /29, but CP will always try send largest possible subnet, which would be at least /24 or larger.&lt;/P&gt;
&lt;P&gt;So, not shockingly enough, Im fairly positive unless you change those values I mentioned to false, you will 100% continue to see this behavior.&lt;/P&gt;
&lt;P&gt;As a matter of fact, this was one of the questions on R81 CCSE exam last year, EXACTLY that : - )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176112#M32196</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T15:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176114#M32198</link>
      <description>&lt;P&gt;Hi Andy&lt;/P&gt;&lt;P&gt;Its the other way around we are having issues, the ASA is sending 172.16.0.0/12 as its source, but the CP is picking networks within this range and building tunnels back to the ASA on all different subnets, the source subnet FROM the Checkpoint is fine, the issue is destinations from the CP towards the ASA. The ASA sees the correct source from the ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176114#M32198</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2023-03-24T15:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176115#M32199</link>
      <description>&lt;P&gt;Fair enough. You got simple diagram you can send with this info and how traffic is supposed to flow? Even basic paint drawing would do, Im not picky, as long as I can visualize this : - )&lt;/P&gt;
&lt;P&gt;PLEASE blur out any sensitive info.&lt;/P&gt;
&lt;P&gt;Tx mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:38:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176115#M32199</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T15:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176116#M32200</link>
      <description>&lt;P&gt;What's &lt;A href="https://community.checkpoint.com/t5/Scripts/One-liner-to-show-VPN-topology-on-gateways/td-p/57975" target="_self"&gt;this tool&lt;/A&gt; showing as encryption domains?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 15:57:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176116#M32200</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-03-24T15:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where does Checkpoint pull the VPN Subnets from for the tunnels ? Strange issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176120#M32201</link>
      <description>&lt;P&gt;Another GREAT tool from you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/687"&gt;@Danny&lt;/a&gt;&amp;nbsp;...keep them coming mate, you are the BEST!! &lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 16:12:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Where-does-Checkpoint-pull-the-VPN-Subnets-from-for-the-tunnels/m-p/176120#M32201</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-24T16:12:20Z</dc:date>
    </item>
  </channel>
</rss>

