<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing between VPNs in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/100632#M7838</link>
    <description>&lt;P&gt;Thanks very much for that information.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2020 08:44:32 GMT</pubDate>
    <dc:creator>alysiakee</dc:creator>
    <dc:date>2020-10-30T08:44:32Z</dc:date>
    <item>
      <title>Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90408#M6912</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need your advice about a VPN routing challenge we have.&lt;/P&gt;&lt;P&gt;As part of the different VON communities we have, we have the following 2 ones:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Office A - Gaia 80.30]&amp;nbsp; &amp;nbsp;&amp;lt;------ S2S Meshed VPN Community ------&amp;gt; [Data Center - Gaia 77.30]&lt;BR /&gt;[Data Center - Gaia 77.30]&amp;nbsp; &amp;lt;----- S2S Meshed VPN Community -----&amp;gt; [AWS Cloud]&lt;/P&gt;&lt;P&gt;Now we would like to allow users in the Office A to connect to instances in AWS.&lt;BR /&gt;Therefore we would need to route the AWS Network through the 1st community to our Data Center and then through the 2nd one to AWS.&lt;/P&gt;&lt;P&gt;We tried to add a IPv4 static routing in the Checkpoint of the Office A to the IP of the one in our Data Center but the traffic is not routed through the community.&lt;/P&gt;&lt;P&gt;I saw several post talking about editing conf file on the router or using some R80 features but there was so many variant that I'm unsure what we should do. Another solution we think about would be to merge both community in a star one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So any advice on how to get this working is welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 13:37:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90408#M6912</guid>
      <dc:creator>dhueber</dc:creator>
      <dc:date>2020-07-02T13:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90429#M6914</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48409"&gt;@dhueber&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Use a star community.&lt;/P&gt;
&lt;P&gt;For more granular control over VPN routing, edit the&lt;STRONG class="bold"&gt; vpn_route.conf&lt;/STRONG&gt; file in the $FWDIR/&lt;STRONG class="bold"&gt;conf/ &lt;/STRONG&gt;directory of the Data Center SMS:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000FF"&gt;[Office A - Gaia 80.30]&lt;/FONT&gt; &amp;lt;-- S2S Star VPN Community ---&amp;gt; &lt;FONT color="#339966"&gt;[Data Center - Gaia 77.30]&lt;/FONT&gt; &amp;lt;--S2S Star VPN Community---&amp;gt; &lt;FONT color="#FF0000"&gt;[AWS Cloud]&lt;/FONT&gt;&lt;/P&gt;
&lt;P class="tpbodytext"&gt;Consider a simple VPN routing scenario consisting of Hub and two Spokes. All machines are controlled from the same Security Management Server, and all the Security Gateways are members of the same VPN community. Only Telnet and FTP services are to be encrypted between the Spokes and routed through the Hub:&lt;/P&gt;
&lt;P class="tpbodytext"&gt;Alhough this could be done easily by configuring a VPN star community, the same goal can be achieved by editing &lt;STRONG class="bold"&gt;vpn_route.conf&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Hop router interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Install on&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#0000FF"&gt;Spoke [Office A - Gaia 80.30]&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#008000"&gt;Hub [Data Center - Gaia 77.30]&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#FF0000"&gt;Spoke [AWS Cloud]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Spoke [AWS Cloud]&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#008000"&gt;Hub [Data Center - Gaia 77.30]&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;FONT color="#0000FF"&gt;Spoke [Office A - Gaia 80.30]&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;And enable VPN routiong to center and to other satellites through center (same on R77.30):&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="star.JPG" style="width: 555px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7085i373D8B7CDF09E8A7/image-dimensions/555x409?v=v2" width="555" height="409" role="button" title="star.JPG" alt="star.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;PS: &lt;BR /&gt;R77.30 is since approximately one year out of support:-)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 19:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90429#M6914</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-07-02T19:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90430#M6915</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48409"&gt;@dhueber&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;migrating to one community with your datacenter as Center and officeA and AWS as satellites would be the best solution.&lt;/P&gt;
&lt;P&gt;Then you have to enable VPN routing on the community and everything should work.&lt;/P&gt;
&lt;P&gt;In your described environment with two communities you can configure VPN routing via vpn_route.conf file.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69726" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk69726&lt;/A&gt;&lt;BR /&gt;It‘s written for an SmartLSM environment but the solution is the same for you.&lt;/P&gt;
&lt;P&gt;Have a look at the documentation&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/13928.htm#o159321" target="_blank" rel="noopener"&gt;Configuration in the VPN Configuration File&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 19:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90430#M6915</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-07-02T19:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90432#M6916</link>
      <description>&lt;P&gt;I see,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp; sent an answer a little bit earlier then me.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 19:42:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90432#M6916</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-07-02T19:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90433#M6917</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;2 seconds faster &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;Best Regards&lt;BR /&gt;Heiko&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 19:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90433#M6917</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-07-02T19:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90434#M6918</link>
      <description>&lt;P&gt;Congratulations&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;you’re the winner today&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;BR /&gt;And we could help&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/48409"&gt;@dhueber&lt;/a&gt;&amp;nbsp;with a solution.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 19:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90434#M6918</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-07-02T19:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90670#M6943</link>
      <description>&lt;P&gt;Hi Heiko,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for the reply and feedback. This is what we thought.&lt;BR /&gt;Won't be the easiest solution to recreate all our VPNs but we will have to go through this process.&lt;/P&gt;&lt;P&gt;Many thanks for taking time to answer&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 13:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/90670#M6943</guid>
      <dc:creator>dhueber</dc:creator>
      <dc:date>2020-07-06T13:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/97966#M7608</link>
      <description>&lt;P&gt;Hello Heiko/Wolgagn,&lt;/P&gt;&lt;P&gt;I had a similar scenario and hoped you could help with a doubt. Our scenario is the same but instead of [AWS cloud] we have a third party Gateway. So in this case i think vpn_route.conf does not apply because it is not possible to define the third party in the "install on" column of the file. I was wondering how to address this. My first option was to migrate to a star community as you described before, but i am not sure if the option "To center and to other satellites trough center" will work with the third party gateway (i think it won't). So if you have any idea to get the same goal with the third party, it would be appreciated. Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 00:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/97966#M7608</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2020-10-01T00:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/97971#M7609</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn routing with third party gateway via star community will be possible.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 05:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/97971#M7609</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-01T05:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/100632#M7838</link>
      <description>&lt;P&gt;Thanks very much for that information.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 08:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/100632#M7838</guid>
      <dc:creator>alysiakee</dc:creator>
      <dc:date>2020-10-30T08:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/106964#M14315</link>
      <description>&lt;P&gt;The issue is when you define the vpn_route.conf file, the install_on column must be the gateway object. I define my remote fw which is Fortinet is Interoperable Device. Below is the issue come out when I tried to install the policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;reading vpn_route.conf: install on gw object is not a firewall (fortinetfw.fortiddns.com)&lt;/P&gt;&lt;P&gt;Do you know how to sort it out ?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 03:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/106964#M14315</guid>
      <dc:creator>nicktran</dc:creator>
      <dc:date>2021-01-05T03:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/116623#M16445</link>
      <description>&lt;P&gt;Hi, i have the same issue with&amp;nbsp;&lt;SPAN&gt;vpn_route.conf. Did you find a solution?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 12:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/116623#M16445</guid>
      <dc:creator>Ara_Zohrabian</dc:creator>
      <dc:date>2021-04-22T12:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between VPNs</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/116625#M16446</link>
      <description>&lt;P&gt;Hi, i have the same issue with &lt;SPAN&gt;vpn_route.conf&lt;/SPAN&gt;. Did you find a solution.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 12:37:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Routing-between-VPNs/m-p/116625#M16446</guid>
      <dc:creator>Ara_Zohrabian</dc:creator>
      <dc:date>2021-04-22T12:37:19Z</dc:date>
    </item>
  </channel>
</rss>

