<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66091#M13522</link>
    <description>&lt;P&gt;Sorry should have added some more additional information&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Remote end A &amp;amp; B are Cisco ASA devices, the head end a Checkpoint R77 gateway .&lt;/P&gt;&lt;P&gt;The Checkpoint Gateway is configured as Star , with VPN domain manually defined subnet's using a group object with the local interesting traffic defined in the group.&lt;/P&gt;&lt;P&gt;The Remote ends are interoperable device with each having a VPN domain manual defined again with another group with the interesting traffic defined for the remote end.&lt;/P&gt;&lt;P&gt;I cannot change the VPN's as this is a live service and traffic works across this from local DMZ's , i just cannot get traffic From A to B via the Checkpoint head end were it traverses two VPN's&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 28 Oct 2019 16:21:35 GMT</pubDate>
    <dc:creator>chip</dc:creator>
    <dc:date>2019-10-28T16:21:35Z</dc:date>
    <item>
      <title>Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66063#M13515</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two working VPN's that terminate on the same head end gateway, let's call them Site A &amp;amp; B for simplicity.&lt;/P&gt;&lt;P&gt;I want to send traffic from Site A to Site B via the same head end , i'm using source and destination NAT's so they aren't in the same encryption domain. I can see traffic coming across the the VPN from site A however i cannot see it being sent over the second VPN to site B it doesn't seem to be encrypting into the second VPN.&lt;/P&gt;&lt;P&gt;Is this possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 14:47:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66063#M13515</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-28T14:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66079#M13520</link>
      <description>&lt;P&gt;I do not really understand your configuration - i would do a Star Community with the head GW as a center and sites A and B as spokes so they are&amp;nbsp;&lt;SPAN&gt;in the same encryption domain. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 15:58:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66079#M13520</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-28T15:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66091#M13522</link>
      <description>&lt;P&gt;Sorry should have added some more additional information&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Remote end A &amp;amp; B are Cisco ASA devices, the head end a Checkpoint R77 gateway .&lt;/P&gt;&lt;P&gt;The Checkpoint Gateway is configured as Star , with VPN domain manually defined subnet's using a group object with the local interesting traffic defined in the group.&lt;/P&gt;&lt;P&gt;The Remote ends are interoperable device with each having a VPN domain manual defined again with another group with the interesting traffic defined for the remote end.&lt;/P&gt;&lt;P&gt;I cannot change the VPN's as this is a live service and traffic works across this from local DMZ's , i just cannot get traffic From A to B via the Checkpoint head end were it traverses two VPN's&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 16:21:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66091#M13522</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-28T16:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66256#M13561</link>
      <description>Are the sites part of the same VPN Community or different ones?&lt;BR /&gt;Does Site A have definition for Site B as part of their encryption configuration (and vice versa)?</description>
      <pubDate>Wed, 30 Oct 2019 14:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66256#M13561</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-30T14:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66260#M13563</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each remote site has unique networks defined&amp;nbsp; so they don't overlap encryption domains , the gateway group has defined the local networks and this is shared between A &amp;amp; B, so to overcome the overlaps i.e networks can't be in local and remote groups i've tried various methods of source and destination NATs either on the Gateway or on Remote A .&lt;/P&gt;&lt;P&gt;To complicate things further on the Gateway to Remote B we are doing source and destination NATs due to duplicate 10 networks at Remote B which is a third party site.&lt;/P&gt;&lt;P&gt;I can see the traffic coming in from remote A which is encrypted&amp;nbsp; / decrpted but doesn't re-encrypt the traffic back to use the second VPN which i don't think is possible, on the remote end i see nothing when i monitor the VPN or packet capture.&lt;/P&gt;&lt;P&gt;I think the interesting traffic is only processed once, is that correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 15:00:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66260#M13563</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-30T15:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66266#M13565</link>
      <description>&lt;P&gt;Have done this before&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Head Office - Check Point - EncDom = It's Local Networks&lt;/P&gt;&lt;P&gt;Site A - unknown vendor but interoperable device&lt;/P&gt;&lt;P&gt;Site B -&amp;nbsp;unknown vendor but interoperable device&lt;/P&gt;&lt;P&gt;To allow Site A to send to Site B then all that had to do was&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Star Community&lt;/P&gt;&lt;P&gt;Central&amp;nbsp; - Head Office&lt;/P&gt;&lt;P&gt;Satellites - Site A and Site B&lt;/P&gt;&lt;P&gt;VPN Routing - Allow to Centre and Satellites&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Site A and Site B overlap then would need to be NATting at the location as could not have Site A and Site B seen the same at the Head Office.&amp;nbsp; It would not know which Gateway to goto.&lt;/P&gt;&lt;P&gt;So would expect that Site A Enc Domain is actually the NATed IP for Site Aand that Site B Enc Domain is the NATed IP for Site B, the NAT being done at Site A and Site B boxes., ie they are seen as just the NAT address by the other locations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Site A and Site B have to be configured to send traffic for each other over the VPN to the Head Office.&amp;nbsp; &amp;nbsp;How do that will depend upon what boxes they are.&lt;/P&gt;&lt;P&gt;So from Site A then traffic would look like&lt;/P&gt;&lt;P&gt;&amp;nbsp;Network A to Network B NAT, as traffic leaves for Network B NAT then Translate the Source at Site A to be Network A NAT.&amp;nbsp; Encrypt into the VPN tunnel to Head Office.&lt;/P&gt;&lt;P&gt;Traffic arrives as Network A NAT which see's as being from Site A, and destined for Site B NAT which it see's as going to Site B and so routes over using the VPN Routing in the VPN Community&lt;/P&gt;&lt;P&gt;Traffic arrives at Site B from Network A NAT to Network B NAT and translates the destination to be Network B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is how I would configure this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 15:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66266#M13565</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-30T15:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66270#M13566</link>
      <description>&lt;P&gt;Yes tried this doing source and destination NATs for Remote A and making sure they are both unique, tried all sorts of permutations with NATs, ensuring source NAT is in the correct encryption domain&lt;/P&gt;&lt;P&gt;I've even tried on another site to site VPN where i don't have to worry about the source and destination NATs between gateway and remote B which i can't change anything as this is a third party.&lt;/P&gt;&lt;P&gt;Its getting the second encryption working is the issue, in tracker i can see the traffic decrypted from Remote A , is there any way i can check to see the process of re-encryption to remote B ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 16:34:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66270#M13566</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-30T16:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66310#M13578</link>
      <description>&lt;P&gt;Yes tried this doing source and destination NATs for Remote A and making sure they are both unique, tried all sorts of permutations with NATs, ensuring source NAT is in the correct encryption domain&lt;/P&gt;&lt;P&gt;I've even tried on another site to site VPN where i don't have to worry about the source and destination NATs between gateway and remote B which i can't change anything as this is a third party.&lt;/P&gt;&lt;P&gt;Its getting the second encryption working is the issue, in tracker i can see the traffic decrypted from Remote A , is there any way i can check to see the process of re-encryption to remote B ,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 09:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66310#M13578</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-31T09:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66318#M13581</link>
      <description>&lt;P&gt;As said previously&lt;/P&gt;&lt;P&gt;1 Star Community with Site A and Site B as Satellites&lt;/P&gt;&lt;P&gt;Enc Doms for the Site A and Site B simply need to be there Local NATed IP to avoid the overlap with those 3rd Party boxes doing the NAT so YOU do not see an overlap of IP.&lt;/P&gt;&lt;P&gt;Your Box as the Centre&lt;/P&gt;&lt;P&gt;Then under VPN Routing make sure is the middle option allowing the Satelites to talk to each other.&lt;/P&gt;&lt;P&gt;Have you configured like this as this is what it should be to allow the two Satellites to talk to each other.&lt;/P&gt;&lt;P&gt;You will see a VPN Routing log entry showing the traffic from Site A to Site B&lt;/P&gt;&lt;P&gt;Your box should NOT be doing any NAT for this to work.&lt;/P&gt;&lt;P&gt;The Third Party Boxes need to see that the opposite Network is via your Box and pass the traffic into the VPN to you,&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 10:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66318#M13581</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-31T10:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint R77 VPN - Two VPN's terminating on the same gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66369#M13596</link>
      <description>&lt;P&gt;Good news&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a standard office to office VPN working now thanks "&lt;SPAN&gt;Nickel" recommendations , they key bit i was missing was on the VPN option routing to center and other satellites .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I've still got an issue as we are doing source and destination NAT between gateway and remote B as the third party doesn't want to change anything but i'm working to get that changed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks again&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 15:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-R77-VPN-Two-VPN-s-terminating-on-the-same-gateway/m-p/66369#M13596</guid>
      <dc:creator>chip</dc:creator>
      <dc:date>2019-10-31T15:33:12Z</dc:date>
    </item>
  </channel>
</rss>

