<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMS and VSX gateway communication over ipsec tunnel in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240827#M46722</link>
    <description>&lt;P&gt;By commenting&amp;nbsp;&lt;SPAN&gt;#define ENABLE_CPD_AMON MGMT server was able to reach VSX gateway and install policy but I cannot create new interface or virtual system. I see 18191 port traffic is going as clear text. I tried to exclude&amp;nbsp;#define ENABLE_CPD but it doesn't work and now policy push is failing on virtual system with TCP connectivity failure (Port 18191)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In other gateway I see traffic is dropping saying, clear text should be encrypted.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VSX should send it in through ipsec tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Feb 2025 14:23:02 GMT</pubDate>
    <dc:creator>an_technical</dc:creator>
    <dc:date>2025-02-10T14:23:02Z</dc:date>
    <item>
      <title>SMS and VSX gateway communication over ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240795#M46721</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on a deployment where SMS and VSX gateway are separated by cities and communication is over ipsec tunnel.&lt;/P&gt;&lt;P&gt;I commented #define ENABLE_CPD_AMON from implied_rules.def rule and created new rule in access policy to send traffic in vpn.&lt;/P&gt;&lt;P&gt;Will this be enough for management server to communicate with VSX gateway (connectivity from mgmt to VSX, Policy installation etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 10:35:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240795#M46721</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-02-10T10:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMS and VSX gateway communication over ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240827#M46722</link>
      <description>&lt;P&gt;By commenting&amp;nbsp;&lt;SPAN&gt;#define ENABLE_CPD_AMON MGMT server was able to reach VSX gateway and install policy but I cannot create new interface or virtual system. I see 18191 port traffic is going as clear text. I tried to exclude&amp;nbsp;#define ENABLE_CPD but it doesn't work and now policy push is failing on virtual system with TCP connectivity failure (Port 18191)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In other gateway I see traffic is dropping saying, clear text should be encrypted.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VSX should send it in through ipsec tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 14:23:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240827#M46722</guid>
      <dc:creator>an_technical</dc:creator>
      <dc:date>2025-02-10T14:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: SMS and VSX gateway communication over ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240869#M46723</link>
      <description>&lt;P&gt;In general, we do not recommend making this configuration change as you can end up in a situation where you are unable to manage your gateways due to a VPN outage.&lt;BR /&gt;Also, it's best to consult with TAC to ensure you are making the correct changes to implied rules.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2025 20:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240869#M46723</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-10T20:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: SMS and VSX gateway communication over ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240917#M46728</link>
      <description>&lt;P&gt;100% concur with PhoneBoy. &amp;nbsp;I tried this myself long ago, and (amazingly) I got it working... for a short time. &amp;nbsp;It eventually became very problematic and I had to undo this trick. &amp;nbsp;Do not do it this way; avoid it as much as you can.&lt;/P&gt;
&lt;P&gt;You'll need to manage the VSX directly from your remote management server, but not through a VPN or through another VS; the VS0 can protect itself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:06:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SMS-and-VSX-gateway-communication-over-ipsec-tunnel/m-p/240917#M46728</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-02-11T15:06:53Z</dc:date>
    </item>
  </channel>
</rss>

