<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN over VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13694#M952</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Between which peers do you want the VPN ? The CP VPN is created between two GWs and - apart from FW rules - transparent, so a client/server behind one GW can connect using VPN to a client/server behind the other GW.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Dec 2018 08:09:09 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-12-07T08:09:09Z</dc:date>
    <item>
      <title>VPN over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13693#M951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;How can I do vpn tunnel inside another vpn tunnel (check point)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 06:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13693#M951</guid>
      <dc:creator>Artyom_Nikulin</dc:creator>
      <dc:date>2018-12-07T06:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13694#M952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Between which peers do you want the VPN ? The CP VPN is created between two GWs and - apart from FW rules - transparent, so a client/server behind one GW can connect using VPN to a client/server behind the other GW.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 08:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13694#M952</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-12-07T08:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13695#M953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A third-party VPN-client (not CP) is installed on the employee's PC. Also, a&amp;nbsp;third-party VPN-client is installed on an employee’s PC at another office. It is necessary that third-party&amp;nbsp;VPN traffic passes inside the&amp;nbsp;CP VPN tunnel, created between&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;two CP GWs (VPN inside VPN)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 15:19:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13695#M953</guid>
      <dc:creator>Artyom_Nikulin</dc:creator>
      <dc:date>2018-12-07T15:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN over VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13696#M954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scheme like this:&lt;/P&gt;&lt;P&gt;(user, want to OpenVPN server)-----"openVPN secured traffic"----&amp;gt;(CP GW)------"openVPN secured trafic encapsulated to IPSec"---------------------&amp;gt;(CP GW)------"decapsulated from IPSec openVPN secured traffic"-----&amp;gt;(OpenVPN server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you control transport, for some reasons you may incapsulate&amp;nbsp;&lt;SPAN&gt;"openVPN secured trafic encapsulated to IPSec" into GRE tunnel between transport routers (such as cisco). So you can have vpn-in-vpn-in-vpn. OpenVPN traffic inside CheckPoint's VPN and CheckPoint's VPN inside GRE tunnel. Also you may create IPSec vpn between CP and 3rd party hardware. You should show your "path" of traffic for better understanding situation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For this minimal scheme, you must add user and server in vpn encryption domain on CP sides, add both CP into same VPN community. CP will create VPN between they and encrypt "openVPN traffic" between user and server&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2018 03:33:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-over-VPN/m-p/13696#M954</guid>
      <dc:creator>AlexeyB</dc:creator>
      <dc:date>2018-12-10T03:33:43Z</dc:date>
    </item>
  </channel>
</rss>

