<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec VPN with both gateways in the same subnet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260428#M51072</link>
    <description>&lt;P&gt;Thank you for all your comments - looks like more diagnosis on the underlying issue is required.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Oct 2025 08:19:49 GMT</pubDate>
    <dc:creator>MattGo</dc:creator>
    <dc:date>2025-10-21T08:19:49Z</dc:date>
    <item>
      <title>IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260144#M51021</link>
      <description>&lt;P&gt;Hello everyone, does anyone know if it is possible to configure a site-to-site VPN between two Check Point R81.20 gateways that are within the same subnet?&amp;nbsp; The client has two data centres linked at layer 2 and want an encrypted tunnel, but at layer 3 it's the same subnet, with one gateway at either end of the link.&amp;nbsp; Unfortunately I do not have sight of the configuration as it's in a secure environment but it seems that the tunnel is not coming up and I was wondering if it is simply never going to work without other changes (e.g. using different subnets) or whether to continue diagnostics work. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 09:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260144#M51021</guid>
      <dc:creator>MattGo</dc:creator>
      <dc:date>2025-10-17T09:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260145#M51022</link>
      <description>&lt;P&gt;Yup...just assign empty group as enc. domain on both fws.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 09:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260145#M51022</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-17T09:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260173#M51029</link>
      <description>&lt;P&gt;I believe not. To send the traffic encrypted from one site to another your gateways must work as Layer 3 routing device.&lt;/P&gt;
&lt;P&gt;If your datacenter is connected via Layer 2, why not using encryption features of the Layer 2 devices like MACSec?&lt;/P&gt;
&lt;P&gt;Or as an idea you can create a VXLAN tunnel for your Layer 2 subnet see&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk170014" target="_blank"&gt;sk170014 - Virtual Extensible LAN (VXLAN) Configuration Guide&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 12:45:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260173#M51029</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-10-17T12:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260183#M51030</link>
      <description>&lt;P&gt;Im fairly sure we got this working before the way I mentioned.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 16:11:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260183#M51030</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-17T16:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260184#M51031</link>
      <description>&lt;P&gt;As in a collection of networks behind one firewall, a different collection of networks behind the other firewall, and the two firewalls are connected with no routers between them? Works fine. VPN termination functionality is just traffic which rides on top of routing functionality. If they can ping each other, they can negotiate IKE and IPSec.&lt;/P&gt;
&lt;P&gt;If the networks behind each firewall overlap, it won't work, but that has nothing to do with the topology of the environment between them.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 16:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260184#M51031</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-10-17T16:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260193#M51035</link>
      <description>&lt;P&gt;True that!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Oct 2025 18:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260193#M51035</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-17T18:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260428#M51072</link>
      <description>&lt;P&gt;Thank you for all your comments - looks like more diagnosis on the underlying issue is required.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2025 08:19:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260428#M51072</guid>
      <dc:creator>MattGo</dc:creator>
      <dc:date>2025-10-21T08:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260953#M51198</link>
      <description>&lt;P&gt;Let us know how it gets solved...cheers.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2025 01:52:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/260953#M51198</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-27T01:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/261539#M51264</link>
      <description>&lt;P&gt;If you configure S2S and both sites have the same subnet, you need to add a NAT rule to translate both your local subnet and the remote subnet on the other site.&lt;/P&gt;&lt;P&gt;Description below:&lt;BR /&gt;In the Communities settings, you still define the actual local and remote subnets. Then, you need to create two different subnets for the NAT configuration.&lt;/P&gt;&lt;P&gt;At this point, both sites must allow firewall rules for those NAT subnets instead of allowing the real subnets.&lt;BR /&gt;After doing so, each site will only see the other’s NAT subnet, not the real IPs.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 03:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/261539#M51264</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2025-10-31T03:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN with both gateways in the same subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/261588#M51273</link>
      <description>&lt;P&gt;That's correct if the gateways have the same subnet behind them. That doesn't sound like what's going on here. This environment sounds like a normal VPN topology, except instead of the Internet with a bunch of routers between the firewalls, it's a switched path (or a pseudowire or something similar).&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 14:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-with-both-gateways-in-the-same-subnet/m-p/261588#M51273</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-10-31T14:21:15Z</dc:date>
    </item>
  </channel>
</rss>

