<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Re-Route Traffic Between Two VPN Tunnels in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222317#M42589</link>
    <description>&lt;P&gt;Thanks Andy, are you referring to "enable route injection mechanism"? (print screen attached)&lt;/P&gt;&lt;P&gt;If so, should I enable it for the community B or both A and B?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Jul 2024 01:03:16 GMT</pubDate>
    <dc:creator>Shurik</dc:creator>
    <dc:date>2024-07-31T01:03:16Z</dc:date>
    <item>
      <title>Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222314#M42587</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Hello Colleagues!&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;I need to implement some workaround... I have policy based VPN tunnel with company A and route based (BGP) tunnel with company B. Company A should get to company B through my gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two separate tunnels that works fine, but traffic from A to B doesn't work. I can access both A and B without any problem.&lt;/P&gt;&lt;P&gt;I see traffic from A gets to my gateway, but goes no where...&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a specific configuration that should be done in order to send traffic from A (10.10.10.0/24) to B (10.20.20.0/24) through the same my gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see attached diagram.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 31 Jul 2024 00:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222314#M42587</guid>
      <dc:creator>Shurik</dc:creator>
      <dc:date>2024-07-31T00:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222315#M42588</link>
      <description>&lt;P&gt;Make sure routing is enabled for vpn under community setting, tunnel management.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 00:45:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222315#M42588</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-31T00:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222317#M42589</link>
      <description>&lt;P&gt;Thanks Andy, are you referring to "enable route injection mechanism"? (print screen attached)&lt;/P&gt;&lt;P&gt;If so, should I enable it for the community B or both A and B?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 01:03:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222317#M42589</guid>
      <dc:creator>Shurik</dc:creator>
      <dc:date>2024-07-31T01:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222318#M42590</link>
      <description>&lt;P&gt;Im not super familiar with SMB appliances, so not sure if that would be equal to route method on regular vpn community in smart console.&lt;/P&gt;
&lt;P&gt;Like below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Routing-between-VPNs/td-p/90408" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Routing-between-VPNs/td-p/90408&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 01:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222318#M42590</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-31T01:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222391#M42609</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/35933"&gt;@Shurik&lt;/a&gt;&amp;nbsp;Sorry, forgot to update this. Here is what I was referring to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27057i8CB518A84B800FB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;A href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/xPIK8IRZF4anBq5LqvwFRQ2.htm?cshid=xPIK8IRZF4anBq5LqvwFRQ2" target="_blank"&gt;VPN Communities - VPN Routing (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;VPN Routing Options&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 31 Jul 2024 16:43:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222391#M42609</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-31T16:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222401#M42610</link>
      <description>&lt;P&gt;Thank you! I got it resolved, looks like starting R80.40 we don't need to specify the encryption domain (center gateway), it should be empty group. Once it was removed, it resolved the problem.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 18:21:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222401#M42610</guid>
      <dc:creator>Shurik</dc:creator>
      <dc:date>2024-07-31T18:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Re-Route Traffic Between Two VPN Tunnels</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222403#M42611</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 18:43:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Re-Route-Traffic-Between-Two-VPN-Tunnels/m-p/222403#M42611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-31T18:43:38Z</dc:date>
    </item>
  </channel>
</rss>

