<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB central management  and VPN tunnel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82765#M16734</link>
    <description>&lt;P&gt;hmmm in&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/masters on SMB&lt;/SPAN&gt; I see Policy, Log and Alert "CHeckpoint_MGMT" (the name from management dashboard) should I replace them with NATed IP address of SMS?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 12:05:19 GMT</pubDate>
    <dc:creator>marcinw</dc:creator>
    <dc:date>2020-04-22T12:05:19Z</dc:date>
    <item>
      <title>SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82739#M16723</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Quick question. In order to makes SMB 1550 firewall "centrally managed" , do I have to create VPN tunnel to Security Gateway and to be connected to Security Management Server via VPN through or VPN has nothing to do with this and I can be connected directly without VPN ? Thank you for responses.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 08:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82739#M16723</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2020-04-22T08:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82743#M16724</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;you don't need any VPN to connect your Management Server to any Gateway. You just add the new Device with the external IP address and initialize the SIC as you would do with any Gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So you don't need a VPN for the "centrally managed" Gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 08:53:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82743#M16724</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2020-04-22T08:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82745#M16725</link>
      <description>&lt;P&gt;Thanks for reply,&lt;/P&gt;&lt;P&gt;I asked this question because I am struggling with adding 1550 to Open server SMS that is place behind Open server Gateway. Half of my lab is on ESXI the only "live" device is 1550 . I am getting message according what you see on the screenshot in attachment , but sometimes I am able to get policies, In dashboard of SMS 1550 is "green" and full visible. I tried many things , unfortunately all failed:&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102712" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102712&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66381" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66381&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I can't figure out what is the reason ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 09:24:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82745#M16725</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2020-04-22T09:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82748#M16726</link>
      <description>&lt;P&gt;I have the identical setup and had no issues - could establish SIC, SMS receives Logs and Policy Pull from SMB works, too. The SMS has a Static NAT IP ( x.y.z.198 behind GW&amp;nbsp;x.y.z.190), i would suggest to configure it like that.&lt;/P&gt;
&lt;P&gt;I can see no screenshot, but would consult the logs first.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 09:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82748#M16726</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-04-22T09:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82755#M16727</link>
      <description>&lt;P&gt;I have no idea why attachment is being scanned all the time anyway I see message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="security-mgmt-section-header-desc"&gt;&lt;SPAN&gt;Security Management Server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="security-mgmt-section-header-desc"&gt;Unreachable: &lt;/SPAN&gt;&lt;SPAN&gt;Security Management server cannot be reached&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="cp-title cp-title-with-separator cp-title-title"&gt;&lt;DIV class="cp-title-text-block"&gt;&lt;SPAN class="cp-title-text"&gt;Security Policy&lt;/SPAN&gt;&lt;DIV class="cp-title-separator"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="x-component x-component-default"&gt;&lt;DIV class="warning_big_icon"&gt;&lt;DIV class="security-mgmt-padded-container"&gt;&lt;SPAN class="security-mgmt-section-header"&gt;&lt;SPAN class="security-mgmt-section-header-desc"&gt;Policy Name: &lt;/SPAN&gt;Standard&lt;/SPAN&gt;&lt;DIV class="security-mgmt-list-item"&gt;&lt;UL class="x-list-plain"&gt;&lt;LI&gt;Last policy installation failed: Warning: Attemped to fetch policy from an IP address that is different than the one used to fetch the certificate. Please check the management object's IP address in the SmartDashboard.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nat works fine, 1550 can ping SMS and inversely, what can be wrong ?&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 10:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82755#M16727</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2020-04-22T10:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82759#M16730</link>
      <description>&lt;P&gt;&lt;SPAN&gt;If you configured it following sk66381 all should work! Troubleshooting would start with checking&amp;nbsp;$FWDIR/conf/masters on SMB, then check if files&amp;nbsp;&lt;EM&gt;custom_logserver_ip&lt;/EM&gt;&amp;nbsp;and&amp;nbsp;&lt;EM&gt;custom_mgmt_ip&lt;/EM&gt;&amp;nbsp;are located in &lt;EM&gt;/opt/fw1/conf,&lt;/EM&gt; and check which IP address is configured in them.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 11:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82759#M16730</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-04-22T11:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: SMB central management  and VPN tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82765#M16734</link>
      <description>&lt;P&gt;hmmm in&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/masters on SMB&lt;/SPAN&gt; I see Policy, Log and Alert "CHeckpoint_MGMT" (the name from management dashboard) should I replace them with NATed IP address of SMS?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 12:05:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SMB-central-management-and-VPN-tunnel/m-p/82765#M16734</guid>
      <dc:creator>marcinw</dc:creator>
      <dc:date>2020-04-22T12:05:19Z</dc:date>
    </item>
  </channel>
</rss>

