<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN on Proxy ARP IP Address in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10276#M1453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks for your reply. The issue we have is that we already have VPN tunnels on addresses from the topology table and we need a new VPN tunnel on a routed IP (not in topology). I think these are mutually exclusive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Nov 2017 07:45:32 GMT</pubDate>
    <dc:creator>Kurt_Abela</dc:creator>
    <dc:date>2017-11-17T07:45:32Z</dc:date>
    <item>
      <title>VPN on Proxy ARP IP Address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10274#M1451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to setup a site to site VPN tunnel with a proxied IP address (proxy arp)? i.e. an address which is not on the physical interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;K&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2017 15:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10274#M1451</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2017-11-09T15:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on Proxy ARP IP Address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10275#M1452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;From the &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm"&gt;R80.10 Site-to-Site VPN docs&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;There are several methods that can determine how remote peers resolve the IP address of the local Security Gateway. These settings are configured in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Security Gateway Properties &amp;gt; IPsec VPN &amp;gt; Link Selection&lt;/STRONG&gt;. Remote peers can connect to the local Security Gateway with these settings.&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; font-weight: 300; text-decoration: none; margin: 0.5cm 0cm 3pt; padding: 15px 0pt 0pt;"&gt;Always Use This IP Address:&lt;/P&gt;&lt;P class="" style="color: #333333; background-color: inherit; text-decoration: none; margin: 6pt 0pt; padding: 0pt;"&gt;Configure a certain IP address that is always used. The options are:&lt;/P&gt;&lt;UL class="" style="color: #333333; margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Main address&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The VPN tunnel is created with the Security Gateway main IP address, specified in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;IP Address&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;General Properties&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page of the Security Gateway.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Selected address from topology table&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The VPN tunnel is created with the Security Gateway using a selected IP address chosen from the drop down menu that lists the IP addresses configured in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Topology&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page of the Security Gateway.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;Statically NATed IP&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The VPN tunnel is created using a NATed IP address. This address is not required to be listed in the topology tab.&lt;/LI&gt;&lt;/UL&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;That last option is what you're surely looking for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2017 01:23:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10275#M1452</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-10T01:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on Proxy ARP IP Address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10276#M1453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many Thanks for your reply. The issue we have is that we already have VPN tunnels on addresses from the topology table and we need a new VPN tunnel on a routed IP (not in topology). I think these are mutually exclusive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Nov 2017 07:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10276#M1453</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2017-11-17T07:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on Proxy ARP IP Address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10277#M1454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since this is a per-gateway setting (not a per-tunnel setting), I believe you are correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way you would meet this requirement today would be using Virtual Systems (VSX).&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would have a VS (basically a virtual gateway) that has the configuration you desire.&lt;/P&gt;&lt;P&gt;This VS could enforce the same or different policy, depending on your requirements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Nov 2017 17:07:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10277#M1454</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-17T17:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN on Proxy ARP IP Address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10278#M1455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your suggestions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have natted internet traffic behind another public ip as a workaround to the issue.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2017 22:48:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-on-Proxy-ARP-IP-Address/m-p/10278#M1455</guid>
      <dc:creator>Kurt_Abela</dc:creator>
      <dc:date>2017-11-23T22:48:30Z</dc:date>
    </item>
  </channel>
</rss>

