<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN routing between Two Domain Based IPsec VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56971#M4281</link>
    <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Thank you for the response, The same configuration we had implemented , but when we had a call with the checkpoint support for validation they mention that as the Satellite G/Ws (frontend and backend ) both are 3rd party.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration would be as follows ::&lt;/P&gt;&lt;P&gt;One Community with Checkpoint Fw as center and rest of the two as Satellite.&lt;/P&gt;&lt;P&gt;Note :: We want some new different configuration for this one is because, the one checkpoint suggested needs to have the same VPN phase 1 and 2 parameters for both the third party gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the future we will be having multiple frontend VPN tunnels , so keeping the VPN parameters same would not help really well.&lt;/P&gt;&lt;P&gt;Moreover, if you say there should be two different communities , the could you please let us know how the VPN routing between these two is going to take place.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mrigen Sane&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jun 2019 15:30:03 GMT</pubDate>
    <dc:creator>Mrigen_Sane</dc:creator>
    <dc:date>2019-06-28T15:30:03Z</dc:date>
    <item>
      <title>VPN routing between Two Domain Based IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56873#M4275</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; We have configured two Domain based tunnels as (Satellite G/Ws) and our checkpoint FW 12400 running on R77.30 Jumbo take&amp;nbsp;&amp;nbsp;Take: 302.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ASA &amp;lt;----IPSec VPN(&amp;nbsp;Backend Tunnel)-----&amp;gt; Checkpoint FW 12400&amp;nbsp;&amp;nbsp;&amp;lt;----IPSec VPN &amp;nbsp;(Frontend Tunnel)-----&amp;gt;&amp;nbsp; Cisco PIX FW&lt;/P&gt;&lt;P&gt;So now the question is for the VPN routing and and can we have two different communities with different Phase 1 and 2 parameters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please share any other configuration method you come across under this scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mrigen Sane&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 18:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56873#M4275</guid>
      <dc:creator>Mrigen_Sane</dc:creator>
      <dc:date>2019-06-27T18:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between Two Domain Based IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56886#M4279</link>
      <description>You would have two different VPN communities, one with the backend tunnel, and one with the frontend tunnel.&lt;BR /&gt;Each community can have different Phase 1/2 settings.</description>
      <pubDate>Thu, 27 Jun 2019 22:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56886#M4279</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-27T22:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between Two Domain Based IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56971#M4281</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Thank you for the response, The same configuration we had implemented , but when we had a call with the checkpoint support for validation they mention that as the Satellite G/Ws (frontend and backend ) both are 3rd party.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration would be as follows ::&lt;/P&gt;&lt;P&gt;One Community with Checkpoint Fw as center and rest of the two as Satellite.&lt;/P&gt;&lt;P&gt;Note :: We want some new different configuration for this one is because, the one checkpoint suggested needs to have the same VPN phase 1 and 2 parameters for both the third party gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in the future we will be having multiple frontend VPN tunnels , so keeping the VPN parameters same would not help really well.&lt;/P&gt;&lt;P&gt;Moreover, if you say there should be two different communities , the could you please let us know how the VPN routing between these two is going to take place.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mrigen Sane&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 15:30:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56971#M4281</guid>
      <dc:creator>Mrigen_Sane</dc:creator>
      <dc:date>2019-06-28T15:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between Two Domain Based IPsec VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56996#M4282</link>
      <description>I guess I missed the part where the third party VPN endpoints need to talk to each other.&lt;BR /&gt;Unfortunately, members of the same VPN Community must all use the same encryption settings.&lt;BR /&gt;And, if you're using different VPN communities, cross-community traffic would not normally be allowed.&lt;BR /&gt;Maybe this would work with a Route-Based VPN, as opposed to Domain-Based VPNs, I'm not sure.</description>
      <pubDate>Fri, 28 Jun 2019 22:06:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-routing-between-Two-Domain-Based-IPsec-VPN/m-p/56996#M4282</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-28T22:06:34Z</dc:date>
    </item>
  </channel>
</rss>

