<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-to-Site VPN - Star VPN Routing Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211250#M40021</link>
    <description>&lt;P&gt;Thank you for the official &lt;SPAN&gt;explanation. However, PC-C is a part of the Center GW, not defined in the Encryption Domain that is able to reach PC-B, which is a satellite host part of the Satellite Encryption Domain. When I read this original explanation my assumption was that it would be the case that all traffic sent by the satellite gateway would be encrypted, yet it is the Center gateway that initiates this connection. Hence my question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I then to assume that this will then apply for both Center and Satellite connections to be forced to cross that VPN Tunnel when an ACL is matched?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time!&lt;/P&gt;</description>
    <pubDate>Mon, 15 Apr 2024 09:16:38 GMT</pubDate>
    <dc:creator>HansKazan</dc:creator>
    <dc:date>2024-04-15T09:16:38Z</dc:date>
    <item>
      <title>Site-to-Site VPN - Star VPN Routing Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211217#M40017</link>
      <description>&lt;P&gt;Hello CheckMates&lt;/P&gt;&lt;P&gt;I would like to request some clarification regarding the Star VPN Routing option "To center or through the center to other satellites, to Internet and other VPN targets" (3rd option). When I have the option enabled, it becomes possible for all Center Networks, even the ones not part of the Center-EncDom on the Center Gateway to reach all Satellite EncDom Networks. It will match the ACL and enter the VPN Tunnel, when to my current understanding it is not meant to. Could anyone please clarify as to why this is?&lt;/P&gt;&lt;P&gt;See a small summary of my configuration below, all devices are OpenServers running R81.20 with JHF 53.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="brrr.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25254i7FAE92EB3C5F46A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="brrr.png" alt="brrr.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;DIV&gt;Center Encryption Domain: 172.16.1.0/24&lt;/DIV&gt;&lt;DIV&gt;Satellite Encryption Domain: 192.168.1.0/24&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Center Hosts&lt;/DIV&gt;&lt;DIV&gt;PC-A - 172.16.1.1 (part of Center-EncDom)&lt;/DIV&gt;&lt;DIV&gt;PC-C - 10.10.2.10&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Satellite Host&lt;/DIV&gt;&lt;DIV&gt;PC-B - 192.168.1.1 (part of Satellite-EncDom)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Ping Result&lt;/DIV&gt;&lt;DIV&gt;PC-A -&amp;gt; PC-B reachable, enters VPN-Tunnel&lt;/DIV&gt;&lt;DIV&gt;PC-A -&amp;gt; PC-C reachable local site&lt;/DIV&gt;&lt;DIV&gt;PC-B -&amp;gt; PC-A reachable, enters VPN-Tunnel&lt;/DIV&gt;&lt;DIV&gt;PC-B -&amp;gt; PC-C unreachable&lt;/DIV&gt;&lt;DIV&gt;PC-C -&amp;gt; PC-A reachable local site&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;PC-C -&amp;gt; PC-B reachable, enters VPN-Tunnel (matches ACL, but does not match EncDom)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="brabra.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25255iBABBA1EF8EE1942A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="brabra.png" alt="brabra.png" /&gt;&lt;/span&gt;&lt;P&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;When enabling the 2nd option "To center and to other satellites through center", it works as I intend for it to work. Meaning that PC-C traffic towards PC-B no longer enters the VPN tunnel, gets accepted by the ACL rule and routed into the void. See a ghetto paint version for a topology below.&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vrrvrr.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25256i19A4EA1DBAABDEB5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vrrvrr.png" alt="vrrvrr.png" /&gt;&lt;/span&gt;&lt;P&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ghettology-lab.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25253i557DBF53ADFBB3DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ghettology-lab.png" alt="ghettology-lab.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thank you for any and all comments that would help me better understand the VPN product!&lt;/DIV&gt;</description>
      <pubDate>Sat, 13 Apr 2024 21:32:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211217#M40017</guid>
      <dc:creator>HansKazan</dc:creator>
      <dc:date>2024-04-13T21:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN - Star VPN Routing Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211240#M40018</link>
      <description>&lt;P&gt;This is an official explanation of how those settings work.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;VPN Routing Options&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sun, 14 Apr 2024 23:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211240#M40018</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-14T23:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN - Star VPN Routing Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211249#M40020</link>
      <description>&lt;P&gt;Then why not stay with the second option ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 07:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211249#M40020</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-04-15T07:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN - Star VPN Routing Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211250#M40021</link>
      <description>&lt;P&gt;Thank you for the official &lt;SPAN&gt;explanation. However, PC-C is a part of the Center GW, not defined in the Encryption Domain that is able to reach PC-B, which is a satellite host part of the Satellite Encryption Domain. When I read this original explanation my assumption was that it would be the case that all traffic sent by the satellite gateway would be encrypted, yet it is the Center gateway that initiates this connection. Hence my question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I then to assume that this will then apply for both Center and Satellite connections to be forced to cross that VPN Tunnel when an ACL is matched?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time!&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 09:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211250#M40021</guid>
      <dc:creator>HansKazan</dc:creator>
      <dc:date>2024-04-15T09:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site VPN - Star VPN Routing Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211304#M40046</link>
      <description>&lt;P&gt;"To center, or through the center to other satellites, to internet and other VPN targets" means route ALL traffic through Center gateways (e.g. Internet-bound traffic or traffic to other VPN gateways).&lt;BR /&gt;It's acting as expected.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Apr 2024 15:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-VPN-Star-VPN-Routing-Question/m-p/211304#M40046</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-15T15:38:31Z</dc:date>
    </item>
  </channel>
</rss>

