<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Routing (PBR) and Domain vpn in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-PBR-and-Domain-vpn/m-p/72850#M5559</link>
    <description>&lt;P&gt;This is not true - what the SK states is that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The following features/blades are &lt;EM&gt;not&lt;/EM&gt; supported with PBR:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;IPv6&lt;/LI&gt;
&lt;LI&gt;URL Filtering&lt;/LI&gt;
&lt;LI&gt;IPS&lt;/LI&gt;
&lt;LI&gt;Locally-generated traffic&lt;/LI&gt;
&lt;LI&gt;Security Servers&lt;/LI&gt;
&lt;LI&gt;Data Loss Prevention (DLP) blade&lt;/LI&gt;
&lt;LI&gt;VPN Domain Based&lt;/LI&gt;
&lt;LI&gt;VPN Route Based&lt;/LI&gt;
&lt;LI&gt;Anti-Spam blade&lt;/LI&gt;
&lt;LI&gt;Mail Transfer Agent (MTA) (relevant for Threat Emulation/Threat Extraction/Data Loss Prevention/Anti-Spam blades)&lt;/LI&gt;
&lt;LI&gt;ISP Redundancy&lt;/LI&gt;
&lt;LI&gt;The following applications (which use Check Point Active Streaming [CPAS]):&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;VoIP (H323, SIP, Skinny, etc.)&lt;/LI&gt;
&lt;LI&gt;HTTPS Inspection&lt;/LI&gt;
&lt;LI&gt;HTTP Header Spoofing&lt;/LI&gt;
&lt;LI&gt;HTTP Proxy&lt;/LI&gt;
&lt;LI&gt;IMAP in IPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So you can not&amp;nbsp;&lt;SPAN&gt;use PBR just for a certain network and use Domain vpn with other networks. But you can mix&amp;nbsp;&lt;/SPAN&gt;VPN Domain Based and&amp;nbsp;VPN Route Based, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk109340: Mixing &lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; with Domain &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; on the same Security Gateway&lt;/A&gt;!&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jan 2020 13:25:02 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-01-21T13:25:02Z</dc:date>
    <item>
      <title>Policy Based Routing (PBR) and Domain vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-PBR-and-Domain-vpn/m-p/72839#M5558</link>
      <description>&lt;P&gt;Policy Based Routing sk100500 just shortly states that PBR cannot be used with Domain vpn. If I use PBR just for a certain network, am I able to use Domain vpn with other networks or how does it affect Domain vpn?&lt;/P&gt;&lt;P&gt;My other problem is that we have 2 ISPs and some networks need to be routed via ISP1 and some via ISP2. I currently have many s2s domain vpns via ISP1 and at some point would like to start moving them one-by-one to ISP2, but if PBR doesn't work with domain vpn, I don't see a way to do this with one Gateway cluster? If I remove PBR, either the ISP1 or ISP2 owned network will route wrong with static routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 12:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-PBR-and-Domain-vpn/m-p/72839#M5558</guid>
      <dc:creator>SamiH</dc:creator>
      <dc:date>2020-01-21T12:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing (PBR) and Domain vpn</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-PBR-and-Domain-vpn/m-p/72850#M5559</link>
      <description>&lt;P&gt;This is not true - what the SK states is that:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The following features/blades are &lt;EM&gt;not&lt;/EM&gt; supported with PBR:&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;IPv6&lt;/LI&gt;
&lt;LI&gt;URL Filtering&lt;/LI&gt;
&lt;LI&gt;IPS&lt;/LI&gt;
&lt;LI&gt;Locally-generated traffic&lt;/LI&gt;
&lt;LI&gt;Security Servers&lt;/LI&gt;
&lt;LI&gt;Data Loss Prevention (DLP) blade&lt;/LI&gt;
&lt;LI&gt;VPN Domain Based&lt;/LI&gt;
&lt;LI&gt;VPN Route Based&lt;/LI&gt;
&lt;LI&gt;Anti-Spam blade&lt;/LI&gt;
&lt;LI&gt;Mail Transfer Agent (MTA) (relevant for Threat Emulation/Threat Extraction/Data Loss Prevention/Anti-Spam blades)&lt;/LI&gt;
&lt;LI&gt;ISP Redundancy&lt;/LI&gt;
&lt;LI&gt;The following applications (which use Check Point Active Streaming [CPAS]):&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;VoIP (H323, SIP, Skinny, etc.)&lt;/LI&gt;
&lt;LI&gt;HTTPS Inspection&lt;/LI&gt;
&lt;LI&gt;HTTP Header Spoofing&lt;/LI&gt;
&lt;LI&gt;HTTP Proxy&lt;/LI&gt;
&lt;LI&gt;IMAP in IPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So you can not&amp;nbsp;&lt;SPAN&gt;use PBR just for a certain network and use Domain vpn with other networks. But you can mix&amp;nbsp;&lt;/SPAN&gt;VPN Domain Based and&amp;nbsp;VPN Route Based, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk109340: Mixing &lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; with Domain &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; on the same Security Gateway&lt;/A&gt;!&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 13:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-PBR-and-Domain-vpn/m-p/72850#M5559</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-01-21T13:25:02Z</dc:date>
    </item>
  </channel>
</rss>

