<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268445#M53124</link>
    <description>&lt;P&gt;Example, as promised:&lt;/P&gt;
&lt;P&gt;set routemap ospf-to-bgp-100 id 10 match prefix-list VOIP_PL_OUT preference 10 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 10 match protocol ospf2&lt;BR /&gt;set routemap ospf-to-bgp-100 id 10 action localpref 100&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 allow&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 match prefix-list VOIP_PL_OUT preference 10 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 match protocol ospf2ase&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*********************&lt;/P&gt;
&lt;P&gt;set prefix-list VOIP_PL_OUT sequence-number 10 prefix x.x.x.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 20 prefix x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 30 prefix 172.27.0.0/16 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 40 prefix x.x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 50 prefix x.x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 80 prefix 10.224.1.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 90 prefix 10.224.98.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 100 prefix 10.224.99.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 110 prefix 172.17.10.0/24 all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jan 2026 15:53:38 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-01-23T15:53:38Z</dc:date>
    <item>
      <title>Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268391#M53104</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We're currently converting our network from static to dynamic routing with BGP. I use a firewall for many site-to-site VPN's we have, so i need to advertise networks that are not in the routing table.&lt;/P&gt;&lt;P&gt;I cannot use Routing Injection Mechanism, because for this i need permanent tunnels and they're only available between two Check Point gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought of using NAT-Pools as they're available to redistribute and able to be added to a route map. However I also see that it's possible to create static blackhole routes and redistribute them the same way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the benefit of using one over the other? The only thing i see is that you cannot do route aggregation with NAT-Pools.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will the site-to-site VPN's remain to work when i add a blackhole route for that network? What has precedence? A blackhole route, or a VPN community?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 11:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268391#M53104</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T11:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268424#M53114</link>
      <description>&lt;P&gt;When labbing, creating a static blackhole route (even when it's less specific than the encryption domain), traffic doesn't pass. So it seems that a static blackhole route is not an option, and the only option i have is creating NAT Pools.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:01:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268424#M53114</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T15:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268427#M53115</link>
      <description>&lt;P&gt;Hey Joe,&lt;/P&gt;
&lt;P&gt;Do you have anything configured as per below?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32893iDA7F1DE970BCD5B6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32894i6F26413D6FE69875/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;  &lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:13:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268427#M53115</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T15:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268435#M53118</link>
      <description>&lt;P&gt;My configuration is below (left out all the snippets that are not relevant):&lt;/P&gt;&lt;PRE&gt;set nat-pool 172.16.160.0/21&lt;BR /&gt;set nat-pool 172.16.160.0/21 comment "Customer support client VPN range"&lt;BR /&gt;&lt;BR /&gt;set routemap export_all_to_bgp id 1 on&lt;BR /&gt;set routemap export_all_to_bgp id 1 match protocol nat-pool&lt;BR /&gt;set routemap export_all_to_bgp id 1 match protocol direct&lt;BR /&gt;&lt;BR /&gt;set bgp external remote-as 65000.3 export-routemap export_all_to_bgp preference 1 on&lt;/PRE&gt;&lt;P&gt;Output of "show route" (you see, there's no entry for the 172.16.160.0/21 network, as this is remote access VPN as example):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;FW3&amp;gt; show route
Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),
       O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),
       IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),
       A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,
       NP - NAT Pool, U - Unreachable, i - Inactive

S               0.0.0.0/0           via x.x.x.x, bond1, cost 0, age 20839158
S               10.0.0.0/8          via 172.16.1.31, bond2, cost 0, age 4353068
S               10.5.0.0/16         via 172.16.1.40, bond2, cost 0, age 4353068
S               10.100.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.101.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.102.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.103.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.104.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.105.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.106.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.107.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.108.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.109.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
S               10.110.0.0/16       via 172.16.1.40, bond2, cost 0, age 4353068
S               10.111.0.0/16       via 172.16.1.40, bond2, cost 0, age 4353068
S               10.112.0.0/16       via 172.16.1.40, bond2, cost 0, age 4353068
S               10.116.0.0/16       via 172.16.1.34, bond2, cost 0, age 4353068
C               127.0.0.0/8         is directly connected, lo
S               172.16.0.0/12       via 172.16.1.31, bond2, cost 0, age 4353068
C               172.16.1.0/24       is directly connected, bond2
                                        LAN
C               172.16.7.16/30      is directly connected, bond0
                                        Sync
S               172.16.23.0/24      via 172.16.1.34, bond2, cost 0, age 4353068
S               172.16.25.0/24      via 172.16.1.34, bond2, cost 0, age 4353068
S               192.168.0.0/16      via 172.16.1.31, bond2, cost 0, age 4353068&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268435#M53118</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T15:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268436#M53119</link>
      <description>&lt;P&gt;I dont believe you need this line:&lt;/P&gt;
&lt;PRE&gt;set routemap export_all_to_bgp id 1 match protocol nat-pool&lt;/PRE&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:37:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268436#M53119</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T15:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268437#M53120</link>
      <description>&lt;P&gt;Yes that is needed, because i actually need to inject this network into BGP (or any dynamic protocol for that matter). I cannot redistribute this network from any other protocol as a route simply doesn't exist for this network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;See also my "show route" output i provided as update on earlier post.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:39:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268437#M53120</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T15:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268439#M53121</link>
      <description>&lt;P&gt;Give me few mins, will send you an example my colleague and I did for a large customer few years ago that worked fine.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268439#M53121</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T15:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268441#M53122</link>
      <description>&lt;P&gt;I can redistribute from NAT pool or a route map, that really doesn't matter for the challenge ahead. It's more the question if there's any other possibility that I've overlooked&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Redistributing from a route map because then for every other BGP peer i only have to redistribute from that routemap, and not select all protocols for each peer.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268441#M53122</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T15:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268444#M53123</link>
      <description>&lt;P&gt;Yeah, blackhole routes eat the traffic between I and o.&lt;/P&gt;
&lt;P&gt;Why not just add static routes sending the traffic out to your default gateway? Then the route would exist, and you could redistribute it from static into BGP.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268444#M53123</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-01-23T15:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268445#M53124</link>
      <description>&lt;P&gt;Example, as promised:&lt;/P&gt;
&lt;P&gt;set routemap ospf-to-bgp-100 id 10 match prefix-list VOIP_PL_OUT preference 10 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 10 match protocol ospf2&lt;BR /&gt;set routemap ospf-to-bgp-100 id 10 action localpref 100&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 allow&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 match prefix-list VOIP_PL_OUT preference 10 on&lt;BR /&gt;set routemap ospf-to-bgp-100 id 20 match protocol ospf2ase&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*********************&lt;/P&gt;
&lt;P&gt;set prefix-list VOIP_PL_OUT sequence-number 10 prefix x.x.x.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 20 prefix x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 30 prefix 172.27.0.0/16 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 40 prefix x.x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 50 prefix x.x.x.x.0/24 exact&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 80 prefix 10.224.1.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 90 prefix 10.224.98.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 100 prefix 10.224.99.0/24 all&lt;BR /&gt;set prefix-list VOIP_PL_OUT sequence-number 110 prefix 172.17.10.0/24 all&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 15:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268445#M53124</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T15:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268448#M53126</link>
      <description>&lt;P&gt;That would also be a very cool idea that I've not yet thought of. Thanks for the insights.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 16:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268448#M53126</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T16:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268449#M53127</link>
      <description>&lt;P&gt;Will lab this to see if a network that is not connected but is inside of a prefix list get's redistributed, thanks for the insights!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 16:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268449#M53127</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-23T16:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268450#M53128</link>
      <description>&lt;P&gt;Great! If you need any more info, let me know.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 16:02:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268450#M53128</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-23T16:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268509#M53141</link>
      <description>&lt;P&gt;nat pools&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk179549" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk179549&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 07:50:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268509#M53141</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2026-01-24T07:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268515#M53142</link>
      <description>&lt;P&gt;That might be it.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jan 2026 09:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268515#M53142</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-24T09:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268578#M53146</link>
      <description>&lt;P&gt;Looks like link&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54489"&gt;@CheckPointerXL&lt;/a&gt;&amp;nbsp;sent is definitely related.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jan 2026 22:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268578#M53146</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-25T22:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268620#M53157</link>
      <description>&lt;P&gt;That was also what i was referring to in my original post. Haven't linked the SK though.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 11:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268620#M53157</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-26T11:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advertising non existing networks (encryption domain) into BGP - Blackhole Route or NAT-Pools</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268621#M53158</link>
      <description>&lt;P&gt;Thanks, that was also what i was referring to in my post, haven't seen the SK yet so thanks for that!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 11:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Advertising-non-existing-networks-encryption-domain-into-BGP/m-p/268621#M53158</guid>
      <dc:creator>joerivang</dc:creator>
      <dc:date>2026-01-26T11:46:08Z</dc:date>
    </item>
  </channel>
</rss>

