<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manually define local VPN Domain per remote peer in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52407#M10376</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;look for&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;subnet_for_range_and_peer&lt;BR /&gt;&lt;BR /&gt;in the crypt.def file&lt;/PRE&gt;</description>
    <pubDate>Thu, 02 May 2019 11:45:55 GMT</pubDate>
    <dc:creator>Andreas_Aust</dc:creator>
    <dc:date>2019-05-02T11:45:55Z</dc:date>
    <item>
      <title>Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52390#M10371</link>
      <description>&lt;P&gt;I'm quite sure I have seen a KB article about a definition file, which allows you to define the local encryption Domain according to the remote peer, e.g.&lt;/P&gt;&lt;P&gt;If the remote site-to-site VPN peer is A, then my local encryption domain are my networks A1, A2 and A3&lt;/P&gt;&lt;P&gt;If the remote site-to-site VPN peer is B, then my local encryption domain are my networks B1 and B2&lt;/P&gt;&lt;P&gt;Can't find that info anymore&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 08:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52390#M10371</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-05-02T08:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52397#M10374</link>
      <description>&lt;P&gt;The options for granular control over VPN routing are available by editing the vpn_route.conf file in the conf directory of the Security Management Server. See Site to Site VPN Administration Guide R80.20 p. 72ff for details !&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 10:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52397#M10374</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-05-02T10:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52402#M10375</link>
      <description>It's not only VPN-Routing. I want a dedicated VPN-Domain definition per remote peer for my GW. Consider the situation, where I have my corporate gateway, which has 20 site-to-site connections with various partners.&lt;BR /&gt;My gateway has 1 single enryption domain definition defined as a group, which includes ALL possible networks it might negotiate with ALL peer gateways.&lt;BR /&gt;To be sure, that my gateway uses only a very well defined set of networks for its negotiation with a specific remote peer, i would need a specific local encryption domain for every peer. This is not possible within the SmartDashboard, but I'm pretty sure I saw this possibility within a config file.&lt;BR /&gt;If this can be achieved with vpn_route.conf, I would be glad to see an example of how it would look like according to the scenario described in my original post.</description>
      <pubDate>Thu, 02 May 2019 10:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52402#M10375</guid>
      <dc:creator>peter_schumache</dc:creator>
      <dc:date>2019-05-02T10:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52407#M10376</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;look for&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;subnet_for_range_and_peer&lt;BR /&gt;&lt;BR /&gt;in the crypt.def file&lt;/PRE&gt;</description>
      <pubDate>Thu, 02 May 2019 11:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52407#M10376</guid>
      <dc:creator>Andreas_Aust</dc:creator>
      <dc:date>2019-05-02T11:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52415#M10378</link>
      <description>&lt;P&gt;Yes, see scenario one here: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk108600: VPN Site-to-Site with 3rd &lt;STRONG&gt;party.&amp;nbsp;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The trickiest part of this is ensuring you are editing the correct user.def file based on the &lt;EM&gt;&lt;STRONG&gt;gateway&lt;/STRONG&gt;&lt;/EM&gt; version, for that see here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98239" target="_blank" rel="noopener"&gt;sk98239 - Location of 'user.def' files on Security Management Server&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 13:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52415#M10378</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-02T13:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52429#M10379</link>
      <description>Yep, user.def is the way to go.&lt;BR /&gt;They are promising us that local per-vpn topology will be possible in a soon to be released version.&lt;BR /&gt;How soon? We'll have to wait and see.</description>
      <pubDate>Thu, 02 May 2019 14:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52429#M10379</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-02T14:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Manually define local VPN Domain per remote peer</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52554#M10406</link>
      <description>Targeted to R80.30.M1 in maintrain: &lt;A href="https://community.checkpoint.com/t5/Multi-Domain-Management/VPN-Domain-per-VPN-community/td-p/30246" target="_blank"&gt;https://community.checkpoint.com/t5/Multi-Domain-Management/VPN-Domain-per-VPN-community/td-p/30246&lt;/A&gt;&lt;BR /&gt;May also be available in a customer-specific release thru your local office.</description>
      <pubDate>Fri, 03 May 2019 21:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manually-define-local-VPN-Domain-per-remote-peer/m-p/52554#M10406</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-03T21:34:58Z</dc:date>
    </item>
  </channel>
</rss>

