<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN community routing not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247838#M52502</link>
    <description>&lt;P&gt;Looks like we have it configured the same as in your screen shot.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2025 16:43:00 GMT</pubDate>
    <dc:creator>isuckatthis</dc:creator>
    <dc:date>2025-04-30T16:43:00Z</dc:date>
    <item>
      <title>VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247826#M52496</link>
      <description>&lt;P&gt;Hello smarter than I people!&lt;BR /&gt;&lt;BR /&gt;I have a Checkpoint to Checkpoint VPN. We're using a community. The traffic gets to the Checkpoint FW VPN concentrator and is not routed across the VPN.&lt;BR /&gt;&lt;BR /&gt;How do I troubleshoot this?&lt;BR /&gt;&lt;BR /&gt;The encryption domain on the remote side shows the correct subnets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've attached images showing the community, logs showing the traffic is not encrypted, a traceroute showing the FW is sending the traffic back to the router then the router back to the FW then the FW back to the router until the end of time (or TTL expires).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no idea how to troubleshoot this. Help! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routing.png" style="width: 652px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30366iCD70F0314E093DD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="routing.png" alt="routing.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30367i4B7332EF19A14C05/image-size/large?v=v2&amp;amp;px=999" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trace.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30368i9B00A00DDBB6B582/image-size/large?v=v2&amp;amp;px=999" role="button" title="trace.png" alt="trace.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247826#M52496</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T16:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247827#M52497</link>
      <description>&lt;P&gt;How is routing set in vpn community object?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247827#M52497</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T16:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247831#M52498</link>
      <description>&lt;P&gt;Should I see VPN Community encryption domain routes here?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hub routing table.png" style="width: 679px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30370iB6476B81B528FD56/image-size/large?v=v2&amp;amp;px=999" role="button" title="hub routing table.png" alt="hub routing table.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spoke routing table.png" style="width: 713px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30369iC80921FD58F246B4/image-size/large?v=v2&amp;amp;px=999" role="button" title="spoke routing table.png" alt="spoke routing table.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247831#M52498</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T16:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247835#M52499</link>
      <description>&lt;P&gt;We've got it configured as a hub and spoke. We're not using any dynamic routing protocols so we have Route Injection Mechanism (RIM) disabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn routing.png" style="width: 509px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30371i3EDADCFBD730AB10/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn routing.png" alt="vpn routing.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tunnel management.png" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30373i3FBBA8944D8CFC6C/image-size/large?v=v2&amp;amp;px=999" role="button" title="tunnel management.png" alt="tunnel management.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247835#M52499</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T16:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247836#M52500</link>
      <description>&lt;P&gt;You should.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:40:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247836#M52500</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T16:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247837#M52501</link>
      <description>&lt;P&gt;Which option applies to you here? center only?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;H2&gt;VPN Routing Options&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247837#M52501</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T16:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247838#M52502</link>
      <description>&lt;P&gt;Looks like we have it configured the same as in your screen shot.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247838#M52502</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T16:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247839#M52503</link>
      <description>&lt;P&gt;Right, but is that correct? I ask because if there is routing supposed to happen through the tunnel, that that setting would be incorrect.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:44:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247839#M52503</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T16:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247842#M52504</link>
      <description>&lt;P&gt;Good question and perhaps I'm not understanding your ask. If you're asking dynamic routing protocols, no. We are expecting static routes via the VPN community to handle routing.&lt;BR /&gt;&lt;BR /&gt;I understand that the encryption domain itself handles encryption and routing across the tunnel. Using my original image showing 10.59.78.0/24 within the encryption domain at the remote site, I'm expecting my hub to route the traffic across the tunnel.&lt;BR /&gt;&lt;BR /&gt;Here's a simple diagram of what we're trying to accomplish. The VPN community lists 10.59.78.0/24 on the spoke side. The VPN community lists 10.59.0.0/16 on the hub side.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diagram.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30375i71DBEBFC2578D803/image-size/large?v=v2&amp;amp;px=999" role="button" title="diagram.png" alt="diagram.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247842#M52504</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T16:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247844#M52505</link>
      <description>&lt;P&gt;Ok, so option you have is fine, BUT, here is your issue, you have supernet problem. 10.59.0.0/16 definitely contains the other subnet. Make sure below options are set to FALSE in guidbedit, push policy, reset the tunnel and try again.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_enable_supernet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_use_largest_possible_subnets&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 16:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247844#M52505</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T16:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247845#M52506</link>
      <description>&lt;P&gt;Thanks Andy! I feel like we're getting closer now!&lt;BR /&gt;&lt;BR /&gt;Do I understand correctly, the more specific mask network isn't automatically used, like in traditional routing?&lt;BR /&gt;&lt;BR /&gt;I'll take a look at dbedit, I've seen someone use it before to hack their way through a problem. "oh, the firewall isn't doing what I want? Let's change registry settings!"&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_squinting_face:"&gt;😆&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;Fingers crossed! Thanks for all your help so far, I'll be back!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247845#M52506</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247847#M52507</link>
      <description>&lt;P&gt;I found them! Two are true and one is global.&lt;/P&gt;&lt;P&gt;Since these are all "ike" tagged, is there any impact anywhere else within Checkpoint when I change these settings? We have no production VPNs from a checkpoint firewall so if this only affects IKE, I feel confident in changing these settings. If this could impact any other functionality, I don't feel comfortable until I understand the full impact.&lt;BR /&gt;&lt;BR /&gt;The second option talks about being global and not a true or false.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ike.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30376i1A2A9148DF929686/image-size/large?v=v2&amp;amp;px=999" role="button" title="ike.png" alt="ike.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:12:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247847#M52507</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247848#M52508</link>
      <description>&lt;P&gt;Glad we can help you. Btw, not sure how long you been around CP, but in the old days (R77 and before versions), that was big issue for supernet, specially with Cisco.&lt;/P&gt;
&lt;P&gt;What I mean by that is say Cisco expects /28 subnet, but CP would always send largest possible, ie min /24 or larger. Thats why folks always had to go to guidbedit and change those values.&lt;/P&gt;
&lt;P&gt;In R80 +, thats not really such a huge problem, but I would still verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247848#M52508</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T17:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247850#M52509</link>
      <description>&lt;P&gt;I've been around CP for about 4 months. I'm an amateur and hence the name "isuckatthis"&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":neutral_face:"&gt;😐&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247850#M52509</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247851#M52510</link>
      <description>&lt;P&gt;The routers sends back the traffic because it is being send out unencrypted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Routers sees: dst: 10.59.78.2 it would route this back to the fw. It should see the public IP of the remote peer.&lt;/P&gt;
&lt;P&gt;Between the public peer IPs you should see ike 500 and ESP traffic. No RFC1918 traffic. Router should only see encrtyped traffic.&lt;/P&gt;
&lt;P&gt;So focus on why it is not encrypted. You have checked the remote side encryption domain but also check local side 10.59.78.2 I suspect this host / network is not in local enc domain.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247851#M52510</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-30T17:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247852#M52511</link>
      <description>&lt;P&gt;The source IP of the traffic behind the hub is in the hubs encryption domain object.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:22:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247852#M52511</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247853#M52512</link>
      <description>&lt;P&gt;I would 100% change it to false. I had people change this probably 100+ times before and I had NEVER seen an issue, even when they had multiple vpn communities. Worst thing that could happen is if tunnel did go down, you just reset it and its back up.&lt;/P&gt;
&lt;P&gt;R82 mgmt has all those values false by default.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247853#M52512</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T17:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247855#M52513</link>
      <description>&lt;P&gt;Bummer, no dice.&lt;/P&gt;&lt;P&gt;I set all three values to false, pushed policy to both firewalls, bounced the tunnel.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Same behavior. The hub does not forward across the tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247855#M52513</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247856#M52514</link>
      <description>&lt;P&gt;That sucks...o well. Okay, question...is tunnel showing up from vpn tu?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247856#M52514</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T17:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN community routing not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247860#M52515</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tlist.png" style="width: 720px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30379i441ADA2E35FDF938/image-size/large?v=v2&amp;amp;px=999" role="button" title="tlist.png" alt="tlist.png" /&gt;&lt;/span&gt;It is, I have SAs on both FWs&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 17:39:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-community-routing-not-working/m-p/247860#M52515</guid>
      <dc:creator>isuckatthis</dc:creator>
      <dc:date>2025-04-30T17:39:17Z</dc:date>
    </item>
  </channel>
</rss>

