<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: route based VPN with remote access vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204454#M38557</link>
    <description>&lt;P&gt;Not sure I'm following you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but the empty encdom is on the target peer, as Bob Zimmerman mentions.&lt;BR /&gt;&lt;BR /&gt;Also Remote Access encdom can be separate to global S2S encdom.&lt;/P&gt;&lt;P&gt;You also have encdoms per community available to you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/MicroContent/Resources/MicroContent/MicroContent_VPNSG/EDPC/encryption-domain-per-community.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/MicroContent/Resources/MicroContent/MicroContent_VPNSG/EDPC/encryption-domain-per-community.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 16:31:08 GMT</pubDate>
    <dc:creator>Machine_Head</dc:creator>
    <dc:date>2024-01-29T16:31:08Z</dc:date>
    <item>
      <title>route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204444#M38552</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;we have remote location where we finish our remote access VPN. So there is an VPN community already populated and configured with IPs (hosts and networks).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we would like to configure an Route based VPN, and one of the steps to configure S2S route based VPN is to configure an Empty VPN domain and set this empty VPN domain as default choice.&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VPN-Tunnel-Interfaces.htm?tocpath=Network%20Management%7CNetwork%20Interfaces%7C_____8" target="_blank"&gt;VPN Tunnel Interfaces (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I cannot set an empty VPN domain there as we are already using an domain for Remote Access VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is a correct solution for our case?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 14:39:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204444#M38552</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-29T14:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204449#M38553</link>
      <description>&lt;P&gt;I have not configured a route-based VPN before, but if the perquisite is an empty VPN domain, I would like to think you can accomplish that using the granular VPN domain feature in R80.40+. Once you add the gateway into the VPN community, you should have the option to edit it to a user-defined group on the gateway page.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:19:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204449#M38553</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-01-29T15:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204450#M38554</link>
      <description>&lt;P&gt;What version are you on?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:23:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204450#M38554</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-29T15:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204451#M38555</link>
      <description>&lt;P&gt;Route-based VPNs only require one end to have an empty encryption domain. Just set the peer's to an empty group.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204451#M38555</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-01-29T15:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204452#M38556</link>
      <description>&lt;P&gt;I would not quite agree with that statement fully. We had case with TAC for probably 2 months in 2021 and no matter what we tried and advice we were given, VPN would never work with just as an empty group on azure interoperable object and actual VPN domain group on cluster end.&lt;/P&gt;
&lt;P&gt;After so many hours of troubleshooting and who knows how many sessions, we ended up setting cluster enc domain to empty group as well and got all 5 tunnels working just fine, never had an issue since.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 15:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204452#M38556</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-29T15:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204454#M38557</link>
      <description>&lt;P&gt;Not sure I'm following you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but the empty encdom is on the target peer, as Bob Zimmerman mentions.&lt;BR /&gt;&lt;BR /&gt;Also Remote Access encdom can be separate to global S2S encdom.&lt;/P&gt;&lt;P&gt;You also have encdoms per community available to you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/MicroContent/Resources/MicroContent/MicroContent_VPNSG/EDPC/encryption-domain-per-community.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/MicroContent/Resources/MicroContent/MicroContent_VPNSG/EDPC/encryption-domain-per-community.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 16:31:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204454#M38557</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2024-01-29T16:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204455#M38558</link>
      <description>&lt;P&gt;Not sure what to tell you. It definitely only needs one encryption domain to be empty. It worked that way when I wrote DTAC's troubleshooting guide for route-based VPNs with R60, and I have some VPNs working that way right now.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 16:44:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204455#M38558</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-01-29T16:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204456#M38559</link>
      <description>&lt;P&gt;I know, I was quite surprised myself as well. But, at the end of the day, it works, so not too worried about it : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 16:48:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204456#M38559</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-29T16:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204458#M38560</link>
      <description>&lt;P&gt;Not so sure Im following either lol&lt;/P&gt;
&lt;P&gt;Here is my question. Are you not able to change it as per below screenshot?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24289iC18834F6BDF4687D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 17:48:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204458#M38560</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-29T17:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204504#M38575</link>
      <description>&lt;P&gt;We are on 81.10&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:49:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204504#M38575</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-30T08:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204505#M38576</link>
      <description>&lt;P&gt;Yes we did set it like on the screenshot but we haven't finished the VPN configuration yet. I will keep you updated&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 08:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204505#M38576</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-30T08:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204544#M38578</link>
      <description>&lt;P&gt;Sure thing mate.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204544#M38578</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-30T13:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204552#M38579</link>
      <description>&lt;P&gt;Okay it looks like encryption domains and communities work correctly like on the screenshot.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt; but somehow CheckPoint did break our network. We set route based vpn with vti of lowest possible priority as a backup route to our MPLS. checkpoint started sending traffic via newly created vti.&lt;/P&gt;&lt;P&gt;We are troubleshooting the issue. But your solution works. something else broke up the network&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204552#M38579</guid>
      <dc:creator>adamec</dc:creator>
      <dc:date>2024-01-30T13:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: route based VPN with remote access vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204553#M38580</link>
      <description>&lt;P&gt;Well, as long as it works mate, Im happy : - )&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/route-based-VPN-with-remote-access-vpn/m-p/204553#M38580</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-30T13:26:02Z</dc:date>
    </item>
  </channel>
</rss>

