<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC Star Community - Access resources on the same Public IP configured on the interoperable De in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-Star-Community-Access-resources-on-the-same-Public-IP/m-p/184294#M33859</link>
    <description>&lt;P&gt;The Peer IP is always excluded in the encryption domain by default on Check Point.&lt;BR /&gt;This causes issues with non-Check Point devices.&lt;BR /&gt;Scenario 3 of the following SK discusses this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2023 17:31:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-19T17:31:14Z</dc:date>
    <item>
      <title>IPSEC Star Community - Access resources on the same Public IP configured on the interoperable Device</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-Star-Community-Access-resources-on-the-same-Public-IP/m-p/184252#M33849</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;I consider this a strange request, but will outline the situation.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Star Based IPSEC VPN Community, which is working perfectly fine to external 3rd party.&amp;nbsp; VPN Community is built so client private /16 and external party private /27 can communicate.&amp;nbsp; Essentially the 3rd party use the tunnel to keep printing traffic encrypted to client printers.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, users access 3rd party web portal by an A record with public IP address that differs to the PIP that the Interoperable Device is configured with.&amp;nbsp; Therefore this access is across the native internet, but does passthrough the checkpoint firewall that also peer's the IPSEC Tunnel.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The 3rd party, now wants WebGUI access for users to use an A Record that resolves to the same PIP as the interoperable Device.&amp;nbsp; This access currently does not work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Firewall logging indicates that this traffic attempts to be encrypted across the VPN Community.&amp;nbsp; Eventually it generates an IKE failure "No Response to Peer"&amp;nbsp; &amp;nbsp;I have attached the 1st log of the communication.&amp;nbsp; &amp;nbsp;Trace Route from client site stops at the Checkpoint Firewall.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I don't know if some of my config is wrong in the VPN community or if this is just an expected outcome.&amp;nbsp; I have limited knowledge, of the 3rd party networking configuration, to yet make the suggestion of using split-brain DNS and resolving the A record to a private IP covered by the VPN Community.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Any advise or assistance would be appreciated.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 05:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-Star-Community-Access-resources-on-the-same-Public-IP/m-p/184252#M33849</guid>
      <dc:creator>jfelix</dc:creator>
      <dc:date>2023-06-19T05:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC Star Community - Access resources on the same Public IP configured on the interoperable De</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-Star-Community-Access-resources-on-the-same-Public-IP/m-p/184294#M33859</link>
      <description>&lt;P&gt;The Peer IP is always excluded in the encryption domain by default on Check Point.&lt;BR /&gt;This causes issues with non-Check Point devices.&lt;BR /&gt;Scenario 3 of the following SK discusses this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 17:31:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-Star-Community-Access-resources-on-the-same-Public-IP/m-p/184294#M33859</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-19T17:31:14Z</dc:date>
    </item>
  </channel>
</rss>

