<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN and Encryption Domain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/200591#M37671</link>
    <description>&lt;P&gt;For sure I would prefer to create a complete Mesh VPN. But customer doesn't want to...&lt;/P&gt;&lt;P&gt;As far as I know the same destination ip can be part of several communities (without using NAT).&lt;/P&gt;</description>
    <pubDate>Thu, 14 Dec 2023 08:44:17 GMT</pubDate>
    <dc:creator>BikeMan</dc:creator>
    <dc:date>2023-12-14T08:44:17Z</dc:date>
    <item>
      <title>S2S VPN and Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/197586#M36907</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;Having an issue using VPN between CP peers.&lt;/P&gt;&lt;P&gt;I have 3 peers (R81.10 hfa110) managed by the same CMA: P1, P2, P3.&lt;/P&gt;&lt;P&gt;Each peers have their own private network: N1,N2,N3.&lt;/P&gt;&lt;P&gt;I have 2 communities:&lt;/P&gt;&lt;P&gt;C1: P2-P3&lt;/P&gt;&lt;P&gt;C2:P3-P1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;N2 can reach N3 each other using VPN C1 and it is working fine.&lt;/P&gt;&lt;P&gt;From N1, I have to reach N2 using a MPLS network, BUT when some specifics ip from N1 has to reach some specific IP in N2 we want to use VPN C2.&lt;/P&gt;&lt;P&gt;So, within C1 I have the following encryption domain (defined per community):&lt;/P&gt;&lt;P&gt;P2=N2&lt;/P&gt;&lt;P&gt;P3=N3&lt;/P&gt;&lt;P&gt;And wihtin C2:&lt;/P&gt;&lt;P&gt;P3= few ip within N3&lt;/P&gt;&lt;P&gt;P1=N1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And sometimes communication between N2-N3 doesn't work (vpn errro 01: wrong peer).&lt;/P&gt;&lt;P&gt;Running the vpn overlap_encdom, I have the following error: "Same destination adress can be reached in more the one community. This configuration is not supported."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that really mean an ip can't be part of several communities ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 12:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/197586#M36907</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2023-11-09T12:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN and Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/197619#M36916</link>
      <description>&lt;P&gt;An IP can be a part of several communities, the problem is there are duplicate destination IPs within multiple communities. That is why NAT was invented.&lt;/P&gt;&lt;P&gt;It seems like P3 talks to P1 and P2, why not just make a single Star VPN community and route traffic that way? Or possibly set them all up in a Mesh VPN community?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 15:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/197619#M36916</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2023-11-09T15:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN and Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/200591#M37671</link>
      <description>&lt;P&gt;For sure I would prefer to create a complete Mesh VPN. But customer doesn't want to...&lt;/P&gt;&lt;P&gt;As far as I know the same destination ip can be part of several communities (without using NAT).&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 08:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-and-Encryption-Domain/m-p/200591#M37671</guid>
      <dc:creator>BikeMan</dc:creator>
      <dc:date>2023-12-14T08:44:17Z</dc:date>
    </item>
  </channel>
</rss>

