<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Community Subnet exclusion in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Community-Subnet-exclusion/m-p/11372#M93946</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The crypt.def modifications are&amp;nbsp;based on destination IP.&lt;/P&gt;&lt;P&gt;Destination IPs are presumed to be &lt;EM&gt;unique&lt;/EM&gt; between all defined VPN communities (otherwise, you have bigger issues).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jul 2018 19:56:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-07-20T19:56:58Z</dc:date>
    <item>
      <title>VPN Community Subnet exclusion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Community-Subnet-exclusion/m-p/11371#M93945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a configuration on which I have differents Community (R77.30 GW) and I have some overlapping subnet in the vpn encryption. the first community (community1) include 3 CKPS Gateway, each gateway have a 10.6.x.0/24 on his VPN domain (10.6.1.0/24, for the first gateway, 10.6.2.0/24 for the second, ...) and the communication work fine. I need yet add a new community (community2) to a central location (interoperable gateway - SOPHOS Firewall) and this IG present a 10.0.0.0/8 subnet in his VPN Domain and phase 2 subnet. When I define this new Community, the communication between 10.6.x.0/24 subnet stop working. I have found the 'Excluding subnets in encryption domain from accessing a specific VPN community' - sk86582, that explain the crypt.def management, but since my goal is to exclude the flow between all the 10.6.x.0/24 subnets in the new community (community2), I don't found the way in the crypt.def file to define a specific community to be sure the exclusion are only applied to the community2 ? Does somebody have an idea about this configuration ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BRgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2018 09:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Community-Subnet-exclusion/m-p/11371#M93945</guid>
      <dc:creator>Herve_SCHLECHT</dc:creator>
      <dc:date>2018-07-20T09:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Community Subnet exclusion</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Community-Subnet-exclusion/m-p/11372#M93946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The crypt.def modifications are&amp;nbsp;based on destination IP.&lt;/P&gt;&lt;P&gt;Destination IPs are presumed to be &lt;EM&gt;unique&lt;/EM&gt; between all defined VPN communities (otherwise, you have bigger issues).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2018 19:56:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Community-Subnet-exclusion/m-p/11372#M93946</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-20T19:56:58Z</dc:date>
    </item>
  </channel>
</rss>

