<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to steer web browsing traffic through an ipsec tunnel to Netskope in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197011#M36762</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If you implement the Netskope IPsec tunnel option for traffic steering: the documentation states that you can use PBR;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netskope.com/en/netskope-help/traffic-steering/ipsec/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/traffic-steering/ipsec/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Configure the IPSec tunnels for your vendor’s source identity devices. Use policy-based routing to steer HTTP/HTTPS traffic on ports 80 and 443 through the IPSec tunnels. If you have the Cloud Firewall license, you can also steer non-HTTP(s) traffic like TCP, UDP, and ICMP through the tunnels. To see vendor specific integration guides: IPSec and GRE."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you follow the hyperlink for the vendor-specific integration guide Checkpoint isnt listed;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;How can we leverage sk167135 to steer http and https traffic through a Netskope tunnel?&lt;/P&gt;&lt;P&gt;It sounds like an ideal solution for ABR, but it also sounds like PBR can't be used with route based vpns so this would need to be a domain based VPN(?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Nov 2023 09:33:55 GMT</pubDate>
    <dc:creator>LazarusG</dc:creator>
    <dc:date>2023-11-03T09:33:55Z</dc:date>
    <item>
      <title>How to steer web browsing traffic through an ipsec tunnel to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197011#M36762</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If you implement the Netskope IPsec tunnel option for traffic steering: the documentation states that you can use PBR;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netskope.com/en/netskope-help/traffic-steering/ipsec/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/traffic-steering/ipsec/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Configure the IPSec tunnels for your vendor’s source identity devices. Use policy-based routing to steer HTTP/HTTPS traffic on ports 80 and 443 through the IPSec tunnels. If you have the Cloud Firewall license, you can also steer non-HTTP(s) traffic like TCP, UDP, and ICMP through the tunnels. To see vendor specific integration guides: IPSec and GRE."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If you follow the hyperlink for the vendor-specific integration guide Checkpoint isnt listed;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/" target="_blank"&gt;https://docs.netskope.com/en/netskope-help/integrations-439794/ipsec-and-gre/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;How can we leverage sk167135 to steer http and https traffic through a Netskope tunnel?&lt;/P&gt;&lt;P&gt;It sounds like an ideal solution for ABR, but it also sounds like PBR can't be used with route based vpns so this would need to be a domain based VPN(?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 09:33:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197011#M36762</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2023-11-03T09:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to steer web browsing traffic through an ipsec tunnel to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197039#M36765</link>
      <description>&lt;P&gt;Regarding sk167135 and the table therein which version is your gateway?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 13:04:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197039#M36765</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-03T13:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to steer web browsing traffic through an ipsec tunnel to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197046#M36766</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Product Name: SVN Foundation&lt;BR /&gt;SVN Foundation Version String: R81.10&lt;BR /&gt;SVN Foundation Build Number: 996000057&lt;BR /&gt;SVN Foundation Status: OK&lt;BR /&gt;OS Name: Gaia&lt;BR /&gt;OS Major Version: 3&lt;BR /&gt;OS Minor Version: 10&lt;BR /&gt;OS Build Number: -&lt;BR /&gt;OS SP Major: -&lt;BR /&gt;OS SP Minor: -&lt;BR /&gt;OS Version Level:&lt;BR /&gt;Appliance SN:&lt;BR /&gt;Appliance Name: PowerEdge R730&lt;BR /&gt;Appliance Manufacturer: Other&lt;/P&gt;&lt;P&gt;This is Check Point CPinfo Build 914000234 for GAIA&lt;BR /&gt;[FW1]&lt;BR /&gt;HOTFIX_R81_10_JUMBO_HF_MAIN Take: 94&lt;BR /&gt;HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE&lt;BR /&gt;HOTFIX_GOT_TPCONF_AUTOUPDATE&lt;BR /&gt;HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R81.10 - Build 035&lt;BR /&gt;kernel: R81.10 - Build 036&lt;/P&gt;&lt;P&gt;route based vpn with PBR or even application based routing might make sense but from SK167135 I understand VTI and PBR isnt supported?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 14:37:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197046#M36766</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2023-11-03T14:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to steer web browsing traffic through an ipsec tunnel to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197102#M36770</link>
      <description>&lt;P&gt;The table suggests should be possible from R80.40 and above with VTI / route based?&lt;/P&gt;
&lt;P&gt;Whether that's what's required / supported by Netskope I couldn't say.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 13:35:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197102#M36770</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-04T13:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to steer web browsing traffic through an ipsec tunnel to Netskope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197481#M36891</link>
      <description>&lt;P&gt;thanks - I think it would be really nice to use PBR/ABR with route based vpn and maybe unnumbered vti but I found there is a solution published since 2022;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179920" target="_blank"&gt;Configuring Site-to-Site VPN between a Check Point Gateway and Netskope&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-steer-web-browsing-traffic-through-an-ipsec-tunnel-to/m-p/197481#M36891</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2023-11-08T17:01:54Z</dc:date>
    </item>
  </channel>
</rss>

