<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN - DNS Lookup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185499#M34112</link>
    <description>&lt;P&gt;I believe Calculate IP Based on Network Topology will use the interface that is "closest" to the remote endpoint.&lt;BR /&gt;This is likely a combination of the device routing table and the topology information configured for the remote gateway.&lt;/P&gt;
&lt;P&gt;For what it's worth, in R82, we are expecting to simplify all this.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jul 2023 19:40:24 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-07-03T19:40:24Z</dc:date>
    <item>
      <title>VPN - DNS Lookup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185394#M34103</link>
      <description>&lt;DIV&gt;VPN - DNS Lookup&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;I have a costumer and in your enverioment, he has one SDWAN before the gatewy with 2 ISP (with to FQDN VPN). In the gateway i have only one external interface with private IP.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; Exempla:&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; vpn.xpto.com&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; vpn2.xpto.com&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; IPS1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ISP2&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SDWAN&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;PrivateIP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Gateway&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Internal Network&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;Then i needed to put both FQDN to work and so many test, i could after change some options option in GuiDBedit and VPN Selection. And one determinate order:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;First i changed in VPN Settings &amp;gt; Link Selection &amp;gt; "Source IP address settings...", i select "IP address of chosen interface":&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Ip chosen Interface.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21607iC7711D36A623D092/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Ip chosen Interface.png" alt="Ip chosen Interface.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;After i changed in VPN Settings &amp;gt; Link Selection &amp;gt; "Outgoing Route Selection" and "Setup", i select "IP address of chosen interface":&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Reply the same source.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21608iCADDD9C093793E46/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Reply the same source.png" alt="Reply the same source.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;And the last changed i open GuiDGedit, set option "dnsLookup" in both field "ip_resolution_mechanism" and "ip_resolution_mechanism_GW" (theses fields are in "Network Objects" &amp;gt; Object Gateway.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ip_resolution.png" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21606iA1B7AD204BD5042D/image-dimensions/831x318?v=v2" width="831" height="318" role="button" title="ip_resolution.png" alt="ip_resolution.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;After theses changed, the VPN work fine and stable, but i found some bugs in interface, automaticly the option "Use Dns resolving" is checked and when i open the option"Link Selection" , the interface ask about one value, case i ignore this popup, the VPN continuos work fine, but alwauys i open this option alert about the problem.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="link selection bug.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21609i3AD0967B56883CB6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="link selection bug.png" alt="link selection bug.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;How this case, i have others cases where the config work, but i didn't find any documentation, one example is option "Calculate IP based on network topology" in Link Selection, this option permit balancing VPN over multi links, and this option has a poor documentation.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&amp;nbsp;Sorry for the English, but I'm training to improve, the environment is in version R81.10 take 66. The prints for the post I took inside Demopoint in version R81.20, I can't validate if this function works well in other versions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;This post is for information purposes only and not to complain or help, I am available in case of doubt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Carlos Luz&lt;BR /&gt;CCSA, CCSE, CCTE&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 02 Jul 2023 12:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185394#M34103</guid>
      <dc:creator>carlos_luz</dc:creator>
      <dc:date>2023-07-02T12:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - DNS Lookup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185499#M34112</link>
      <description>&lt;P&gt;I believe Calculate IP Based on Network Topology will use the interface that is "closest" to the remote endpoint.&lt;BR /&gt;This is likely a combination of the device routing table and the topology information configured for the remote gateway.&lt;/P&gt;
&lt;P&gt;For what it's worth, in R82, we are expecting to simplify all this.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 19:40:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185499#M34112</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-03T19:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - DNS Lookup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185520#M34118</link>
      <description>&lt;P&gt;&amp;nbsp;Hello PhoneBoy, yes, with Caculate option i can use routes to chose the interface and IP interface what i use in VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;But we dont have any documentation about this or cases of use.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jul 2023 04:13:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185520#M34118</guid>
      <dc:creator>carlos_luz</dc:creator>
      <dc:date>2023-07-04T04:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN - DNS Lookup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185679#M34140</link>
      <description>&lt;P&gt;All of the options here control what IP address is used to initiate a VPN with a remote peer.&lt;BR /&gt;Unless the peer is accessible via an internal interface, "Calculate IP based on network topology" will generally result in the external (cluster) IP being used.&lt;BR /&gt;This is the default setting.&lt;/P&gt;
&lt;P&gt;Note the settings here apply to ALL VPN peers.&lt;BR /&gt;If you have multiple VPN peers that each require a different IP to be used for different peers, then you will need to use one of the options.&lt;/P&gt;
&lt;P&gt;As I stated previously, we are planning to revamp these options in R82 to simplify things.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 13:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-DNS-Lookup/m-p/185679#M34140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-05T13:54:09Z</dc:date>
    </item>
  </channel>
</rss>

