<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN routing between CP to CP and CP to 3rd Part in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81249#M16416</link>
    <description>If you have overlapping encryption domains, you definitely need NAT, possibly on both ends, to make everything work.</description>
    <pubDate>Wed, 08 Apr 2020 03:38:42 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-04-08T03:38:42Z</dc:date>
    <item>
      <title>VPN routing between CP to CP and CP to 3rd Part</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81102#M16388</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've just managed to set up a site-to-site IPSec tunnel from a 3rd party DAIP GW to one of my centrally managed CP GW clusters. This is working great and traffic flows to and from just fine.&lt;/P&gt;&lt;P&gt;This CP GW cluster also participates in my global mesh community between all my other centrally managed CP GW clusters - this is all working perfectly.&lt;/P&gt;&lt;P&gt;My issue is, I cannot access this new site-to-site tunnel from a GW cluster outside of the one it's directly terminating on.&lt;/P&gt;&lt;P&gt;I'll try and outline below:&lt;/P&gt;&lt;P&gt;[SITE1] &amp;lt;centr. managed vpn - cp to cp&amp;gt; [SITE2]&amp;nbsp;&amp;lt;manually configured vpn - cp to daip&amp;gt; [SITE3]&lt;/P&gt;&lt;P&gt;SITE1 to/from SITE2 = OK&lt;/P&gt;&lt;P&gt;SITE2 to/from SITE3 = OK&lt;/P&gt;&lt;P&gt;SITE 1 to/from SITE3 = FAIL&lt;/P&gt;&lt;P&gt;I've tried including the subnet of SITE3 in the encryption domain of SITE2, to ensure SITE1 knew how to get there as part of the global mesh community, but as this encryption domain is also used with SITE3, it causes the tunnel to drop.&lt;/P&gt;&lt;P&gt;Any idea on what I'm missing here? Any tips you could provide would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 09:14:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81102#M16388</guid>
      <dc:creator>chkrh</dc:creator>
      <dc:date>2020-04-07T09:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between CP to CP and CP to 3rd Part</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81232#M16413</link>
      <description>The encryption domain equivalent defined on Site 3 for the other sites needs to include Site 1 or it won't work.&lt;BR /&gt;Or IP Pool NAT may need to be used.</description>
      <pubDate>Wed, 08 Apr 2020 00:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81232#M16413</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T00:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between CP to CP and CP to 3rd Part</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81248#M16415</link>
      <description>&lt;P&gt;Thanks! The NAT between sites looks like it'll overcome the issue of overlapping encryption domains which I'm stuck on. I'll give it a try.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 03:34:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81248#M16415</guid>
      <dc:creator>chkrh</dc:creator>
      <dc:date>2020-04-08T03:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN routing between CP to CP and CP to 3rd Part</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81249#M16416</link>
      <description>If you have overlapping encryption domains, you definitely need NAT, possibly on both ends, to make everything work.</description>
      <pubDate>Wed, 08 Apr 2020 03:38:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-routing-between-CP-to-CP-and-CP-to-3rd-Part/m-p/81249#M16416</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T03:38:42Z</dc:date>
    </item>
  </channel>
</rss>

