<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway uses VPN despite not being part of the VPN domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186740#M34354</link>
    <description>&lt;P&gt;Yes,&lt;/P&gt;
&lt;P&gt;Check&amp;nbsp;&lt;SPAN&gt;sk108600 scenario 3:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can use crypt.def file to exclude traffic from vpn including src ip, dst ip and ports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jul 2023 18:18:55 GMT</pubDate>
    <dc:creator>RS_Daniel</dc:creator>
    <dc:date>2023-07-18T18:18:55Z</dc:date>
    <item>
      <title>Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186715#M34349</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I´m in the process of setting up a Site2Site VPN from our office to Cisco Umbrella to channel all user surf traffic to the Umbrella "Proxy".&lt;/P&gt;&lt;P&gt;Tunnel is a star community, one tunnel per gateway&lt;/P&gt;&lt;P&gt;My gateway is center and VPN domain is "User-computer-VLAN" (192.168.5.0/24).&lt;/P&gt;&lt;P&gt;Satellite Gateway is the Umbrella gateway with VPN domain "Internet_without_Private_Networks". This is a group-with-exclusion object, consisting of "Internet" except "Private networks (RFC 1918)". The purpose is that the clients shall access all internet IPs through the tunnel, only then being filtered through the Umbrella proxies.&lt;/P&gt;&lt;P&gt;The traffic is then allowed in the ruleset, I also added the community to the rule.&lt;/P&gt;&lt;P&gt;This works nicely but there is a side effect. Every traffic from the gateway itself is also send into the tunnel. This ranges from DNS traffic for ISP redundancy DNS proxy updates to user-VPN-tunnels not working to the gateway to not being able to download updates for IPS and patches.&lt;/P&gt;&lt;P&gt;"Excluded services" might help me with ISP redundancy ping and User-VPN-tunnels but not with the IPS updates. Eventually, Client DNS shall also go through the tunnel, so I can´t exlude that either.&lt;/P&gt;&lt;P&gt;Is there any way I can exclude the gateway from using the tunnel?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;Robin&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 15:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186715#M34349</guid>
      <dc:creator>Robin_H</dc:creator>
      <dc:date>2023-07-18T15:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186740#M34354</link>
      <description>&lt;P&gt;Yes,&lt;/P&gt;
&lt;P&gt;Check&amp;nbsp;&lt;SPAN&gt;sk108600 scenario 3:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can use crypt.def file to exclude traffic from vpn including src ip, dst ip and ports.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 18:18:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186740#M34354</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-07-18T18:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186756#M34360</link>
      <description>&lt;P&gt;Take a look here, the setup should be similar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179920" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk179920&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 20:13:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186756#M34360</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-07-18T20:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186870#M34385</link>
      <description>&lt;P&gt;This is the way I was already going. Good to know that it seems to be the current best-practice.&lt;/P&gt;&lt;P&gt;In this case, putting services in the cloud does not make things easier though.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 15:39:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/186870#M34385</guid>
      <dc:creator>Robin_H</dc:creator>
      <dc:date>2023-07-19T15:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/200880#M37739</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you follow the Cisco guide?&lt;BR /&gt;&lt;A href="https://docs.umbrella.com/umbrella-user-guide/docs/configure-tunnels-with-checkpoint-gaia" target="_blank"&gt;https://docs.umbrella.com/umbrella-user-guide/docs/configure-tunnels-with-checkpoint-gaia&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;do you run a "Domain Based" tunnel or with VTI Tunnel interfaces?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 12:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/200880#M37739</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2023-12-18T12:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway uses VPN despite not being part of the VPN domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/201308#M37850</link>
      <description>&lt;P&gt;We´re not using VTI.&lt;BR /&gt;Our Umbrella contact just mentioned this new guide the other day but switching to it would be too big at the moment.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;We do have an issue with the current setup (IKE SA is not simply renewed or gracefully finished) but that seems related to our usage of MEP, using two different Umbrella DCs in a star community for additional redundancy. Troubleshooting on this will commence soon.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 14:12:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gateway-uses-VPN-despite-not-being-part-of-the-VPN-domain/m-p/201308#M37850</guid>
      <dc:creator>Robin_H</dc:creator>
      <dc:date>2023-12-21T14:12:58Z</dc:date>
    </item>
  </channel>
</rss>

