<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN S2S with same network on local and remote domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191037#M35373</link>
    <description>&lt;P&gt;Hello PhoneBoy,&amp;nbsp;&amp;nbsp;thank you for the quick reply.&lt;/P&gt;&lt;P&gt;For the VPN with community "X" the enabled destination network is a NAT network, 10.97.24.0, with which we do Destination NAT on 10.106.24.0/24. Both are declared in the "user defined" remote domain.&lt;BR /&gt;For VPN with community "X", The source networks of the clients are different from network 10.106.24.0/24, and the traffic works properly.&lt;/P&gt;&lt;P&gt;While for the VPN with community "Y" with network 10.106.0.0/16 declared in the local domain "according to the gateway", only network 10.106.24.0/24, when called by the remote peer, does not work and our VS drops calls by clean up rule. All other networks in 10.106.0.0/16, when called, work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Aug 2023 06:45:56 GMT</pubDate>
    <dc:creator>Marco_Dcr_</dc:creator>
    <dc:date>2023-08-30T06:45:56Z</dc:date>
    <item>
      <title>VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/190919#M35371</link>
      <description>&lt;P&gt;Good morning,&lt;BR /&gt;We have a VSX 15400 cluster, R81.10, with a virtual system acting as a site-to-site vpn terminator.&lt;BR /&gt;Prior to porting to R81.10, we were using a single "vpn domain local" associated with the gateway. Now we have started to use a dedicated "vpn domain" for each community, so we have a hybrid configuration, where some vpn use the "according to the gateway" vpn domain group, while others use the "user defined" group, defined for each community.&lt;/P&gt;&lt;P&gt;We have this situation:&lt;BR /&gt;In the "vpn local domain" associated with the gateway, a network 10.106.0.0/16 is defined.&lt;/P&gt;&lt;P&gt;The need arose to use for a vpn, the network 10.106.24.0/24, as a remote domain. Therefore, a dedicated community "X" was created, defining as vpn domain remote "user defined" this network.&lt;/P&gt;&lt;P&gt;This configuration turns out to work for community "X", but for other vpn, with community "Y", where network 10.106.24.0/24 is defined in the group vpn domain local (according to the gateway), it does not work and the traffic is dropped (clean up rule).&lt;/P&gt;&lt;P&gt;is it possible that the remote VPN domain, used in community "X" as user definded, overrides community "Y" domain local "according to the gateway"? this would explain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that you can help us.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 14:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/190919#M35371</guid>
      <dc:creator>Marco_Dcr_</dc:creator>
      <dc:date>2023-08-29T14:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/190990#M35372</link>
      <description>&lt;P&gt;How would users on the “local”&amp;nbsp;&lt;SPAN&gt;10.106.24.0/24 know when they need to talk to something on the “remote”&amp;nbsp;10.106.24.0/24?&lt;BR /&gt;This won’t work without address translation on both ends.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 21:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/190990#M35372</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-29T21:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191037#M35373</link>
      <description>&lt;P&gt;Hello PhoneBoy,&amp;nbsp;&amp;nbsp;thank you for the quick reply.&lt;/P&gt;&lt;P&gt;For the VPN with community "X" the enabled destination network is a NAT network, 10.97.24.0, with which we do Destination NAT on 10.106.24.0/24. Both are declared in the "user defined" remote domain.&lt;BR /&gt;For VPN with community "X", The source networks of the clients are different from network 10.106.24.0/24, and the traffic works properly.&lt;/P&gt;&lt;P&gt;While for the VPN with community "Y" with network 10.106.0.0/16 declared in the local domain "according to the gateway", only network 10.106.24.0/24, when called by the remote peer, does not work and our VS drops calls by clean up rule. All other networks in 10.106.0.0/16, when called, work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 06:45:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191037#M35373</guid>
      <dc:creator>Marco_Dcr_</dc:creator>
      <dc:date>2023-08-30T06:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191152#M35374</link>
      <description>&lt;P&gt;Do you see key installs from the relevant remote gateway?&lt;BR /&gt;i.e. do you know 100% that the traffic is actually encrypted?&lt;BR /&gt;Again, I would ask the same question of the remote site: how does it know when it's talking to your&amp;nbsp;&lt;SPAN&gt;10.106.24.0/24 or theirs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 18:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191152#M35374</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-30T18:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191187#M35375</link>
      <description>&lt;P&gt;The remote gateway is an SMB 1470 and unfortunately has some problems with logs. Anyway, whatever network is pointed to of major 10.106.0.0/16 works (ex. 10.106.50.10, 10.106.100.10), except for 10.106.24.0/24, where we do not see decrypt on the local gateway (15400), but only drop by blade firewall.&lt;/P&gt;&lt;P&gt;For the remote site, network 10.106.0.0/16 is defined as the "remote domain" of the vpn,&amp;nbsp;no nat is carried out.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 07:51:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191187#M35375</guid>
      <dc:creator>Marco_Dcr_</dc:creator>
      <dc:date>2023-08-31T07:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191259#M35376</link>
      <description>&lt;P&gt;The fact you're not getting traffic to&amp;nbsp;10.106.24.0/24 encrypted means the remote gateway (1470) is not encrypting the traffic.&lt;BR /&gt;&lt;SPAN&gt;Does this network exist behind the 1470 at all?&lt;BR /&gt;What code revision is this appliance running?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 18:12:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191259#M35376</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-31T18:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191308#M35377</link>
      <description>&lt;P&gt;there might be some problem with 1470 since it is at a very old version, 77.20.&lt;BR /&gt;In any case, we wanted to understand if this kind of configuration can also be used in other vpn with other terminators, or it may not work. So having a network 10.106.0.0/16 as Domain Local "according to the gateway," and then using other minor networks (ex. 10.106.24.0/24) of this major as remote domain "user defined " on other vpn (doing d-nat with another network on our fw). Can this work or is the configuration wrong and can it give problems?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 07:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191308#M35377</guid>
      <dc:creator>Marco_Dcr_</dc:creator>
      <dc:date>2023-09-01T07:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191352#M35378</link>
      <description>&lt;P&gt;I can’t speak to how other vendors handle this.&lt;BR /&gt;I can say because 10.106.24.0/24 is included in the specified encryption 10.106.0.0/16, the 1470 will not encrypt traffic sent to it.&lt;BR /&gt;This will need to be addressed through NAT as in the first case.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 14:43:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191352#M35378</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-01T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191491#M35379</link>
      <description>&lt;P&gt;Leaving aside the issue of remote peer SMB 1470, we would like to understand if on the gateway under our management, a virtual system on vsx 15400 cluster, it is possible to use this configuration or it may lead to problems. So having a local network "according to the gateway" 10.106.0.0/16, and a remote network "user defined" on another community, having addressing 10.106.24.0/24, pointing a nat network to reach it.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 13:11:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191491#M35379</guid>
      <dc:creator>Marco_Dcr_</dc:creator>
      <dc:date>2023-09-04T13:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S with same network on local and remote domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191649#M35380</link>
      <description>&lt;P&gt;From a management perspective, there's no issue here as the local encryption domain always needs to include hosts that will ultimately communicate over the VPN.&lt;BR /&gt;If there is overlap between the two gateways (because they use the same address space), then NAT will be required for segments that use the same IP on both sides to talk to each other.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 19:28:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-with-same-network-on-local-and-remote-domain/m-p/191649#M35380</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-05T19:28:27Z</dc:date>
    </item>
  </channel>
</rss>

