<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vpn domain based and eBGP + VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232665#M44953</link>
    <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;I got situation here and Im stucked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are talking about r81.20 VSX 26k SG.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can set eBGP between external router and a Vsys. Vsys can announce own routes and receive routes from external router. But how I can send to external Router a route to a subnet reachead only by vpn domain based?&lt;/P&gt;&lt;P&gt;How I can announce to BGP a (route) vpn domain based ?&lt;/P&gt;&lt;P&gt;The VPN domain based doesnt have routes on the FIB, under # route -n or #ip route show we only can see static routes.&lt;/P&gt;&lt;P&gt;Is there anyway to&amp;nbsp;accomplish this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; Tks a lot,&lt;/P&gt;&lt;P&gt;Victor C&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-11-13_18-41.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28457iC92F3A376281EC97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-11-13_18-41.png" alt="2024-11-13_18-41.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2024 21:43:50 GMT</pubDate>
    <dc:creator>victor_cortez</dc:creator>
    <dc:date>2024-11-13T21:43:50Z</dc:date>
    <item>
      <title>Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232665#M44953</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;I got situation here and Im stucked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are talking about r81.20 VSX 26k SG.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can set eBGP between external router and a Vsys. Vsys can announce own routes and receive routes from external router. But how I can send to external Router a route to a subnet reachead only by vpn domain based?&lt;/P&gt;&lt;P&gt;How I can announce to BGP a (route) vpn domain based ?&lt;/P&gt;&lt;P&gt;The VPN domain based doesnt have routes on the FIB, under # route -n or #ip route show we only can see static routes.&lt;/P&gt;&lt;P&gt;Is there anyway to&amp;nbsp;accomplish this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; Tks a lot,&lt;/P&gt;&lt;P&gt;Victor C&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-11-13_18-41.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28457iC92F3A376281EC97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2024-11-13_18-41.png" alt="2024-11-13_18-41.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 21:43:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232665#M44953</guid>
      <dc:creator>victor_cortez</dc:creator>
      <dc:date>2024-11-13T21:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232667#M44954</link>
      <description>&lt;P&gt;You need to use RIM feature for domain based VPN. Once RIM is activated, you will get content of VPN encryption domain of remote VPN peer as &lt;STRONG&gt;kernel routes. &lt;/STRONG&gt;These kernel routes can be propagated over BGP.&lt;/P&gt;
&lt;P&gt;More info about RIM feature can be found in &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Route-Injection-Mechanism.htm" target="_blank" rel="noopener"&gt;R81.20 Site to Site VPN Administration Guide&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 22:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232667#M44954</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-11-13T22:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232674#M44958</link>
      <description>&lt;P&gt;I agree 100% with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;. All this would be much easier with route based tunnel, as you could just use unnumbered VTIs for BGP. But, for domain based, yes, RIM mechanism seems your best option.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 02:54:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232674#M44958</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-14T02:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232676#M44959</link>
      <description>&lt;P&gt;Hello Josko,&lt;/P&gt;&lt;P&gt;Im reading about RIM and sounds like exaclty what I need. Just to confirm, RIM works fine with VSX, correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tks,&lt;/P&gt;&lt;P&gt;Victor C&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 03:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232676#M44959</guid>
      <dc:creator>victor_cortez</dc:creator>
      <dc:date>2024-11-14T03:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232677#M44960</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48056"&gt;@victor_cortez&lt;/a&gt;&amp;nbsp;yes, RIM is working with VSX, no limitation seen in&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk79700" target="_blank"&gt;sk79700 - VSNext / VSX supported features&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 05:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232677#M44960</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-11-14T05:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232704#M44973</link>
      <description>&lt;P&gt;Yes, it does, no issues there.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 11:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232704#M44973</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-14T11:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232774#M44988</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Im looking here and got stucked once more.&lt;BR /&gt;&lt;BR /&gt;situation 1 - for Vsys XYZ the vpn ipsec we are not defining the subnets in the community, all traffic should go to the tunnel. So in the "interopable device" - topology - group properties - in group - there is only the public Ip of the peer itself.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If im not defining the subnets in the community RIM will work?&lt;BR /&gt;&lt;BR /&gt;1 - I understand is RIM only works as the expected if subnets are defined in the VPN Community.&lt;/P&gt;&lt;P&gt;2 - RIM doesnt work if customized crypt.def and user.defl files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you guys think about this?&lt;/P&gt;&lt;P&gt;Tks,&lt;/P&gt;&lt;P&gt;Victor&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 17:30:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232774#M44988</guid>
      <dc:creator>victor_cortez</dc:creator>
      <dc:date>2024-11-14T17:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232775#M44989</link>
      <description>&lt;P&gt;I believe so as well.&lt;/P&gt;
&lt;P&gt;1-yes&lt;/P&gt;
&lt;P&gt;2-correct&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 17:33:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232775#M44989</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-14T17:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Vpn domain based and eBGP + VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232797#M44994</link>
      <description>&lt;P&gt;For 1.&lt;/P&gt;
&lt;P&gt;- yes, the definition of an encryption domain is necessary&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- you can define an encryption domain for all networks as an example with a range „0.0.0.0 - 254.254.254.254“&lt;/P&gt;
&lt;P&gt;For 2.&lt;/P&gt;
&lt;P&gt;- as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Andy wrote, entries from these special files are ignored.&amp;nbsp;&lt;BR /&gt;- but with the newer releases you can define separate encryption domains for differente VPN communities within SmartConsole, this was the most common use case for changing user.def (I don‘t know which changes you did, but maybe that‘s it)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2024 20:44:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Vpn-domain-based-and-eBGP-VSX/m-p/232797#M44994</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-11-14T20:44:11Z</dc:date>
    </item>
  </channel>
</rss>

