<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access encryption domain in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110001#M20841</link>
    <description>&lt;P&gt;Are there IPs in use on either the client or gateway that overlap with these subjects?&lt;/P&gt;</description>
    <pubDate>Sat, 06 Feb 2021 21:54:51 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-02-06T21:54:51Z</dc:date>
    <item>
      <title>Remote Access encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/109995#M20840</link>
      <description>&lt;P&gt;Good Day everyone.&amp;nbsp; Added to&amp;nbsp; the encryption domain group object for the first time in years, and seeing weird behavior.&amp;nbsp; Prior to my change, the group has a slew of /24 networks, and /32 hosts configed - no issue.&amp;nbsp; Added a few /24 networks, and I'm seeing them carved up - 192.168.26.0 /24 is an example - here's what i get in my routing table after i connect via CP Mobile:&lt;/P&gt;&lt;P&gt;192.168.26.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.255&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254&amp;nbsp; 1&lt;BR /&gt;192.168.26.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.252 &amp;nbsp; &amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254&amp;nbsp; 1&lt;BR /&gt;192.168.26.8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.248&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254 1&lt;BR /&gt;192.168.26.16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.240&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254 1&lt;BR /&gt;192.168.26.32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.224&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254 1&lt;BR /&gt;192.168.26.64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.192&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254 1&lt;BR /&gt;192.168.26.128&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.128&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.253&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.27.253.254 1&lt;/P&gt;&lt;P&gt;I've set "enable_supernet_per_community" to both 0 &amp;amp; 1, neither helped.&amp;nbsp; Clearly i'm missing something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 20:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/109995#M20840</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2021-02-06T20:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110001#M20841</link>
      <description>&lt;P&gt;Are there IPs in use on either the client or gateway that overlap with these subjects?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 21:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110001#M20841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-06T21:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110003#M20842</link>
      <description>&lt;P&gt;Phoneboy makes a good point...overlapping domains.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 22:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110003#M20842</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-06T22:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110010#M20843</link>
      <description>&lt;P&gt;Thank you both for your replies, much appreciated.&lt;/P&gt;&lt;P&gt;I wasn't receiving the policy push warning about overlapping domains, but when i ran "vpn overlap_encdom" on the gateway, i saw that there is quite a few.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the layout - I have (8) internal sites that all participate in a meshed community.&amp;nbsp; Each of them have their locally connected networks as their encryption domain.&amp;nbsp; I also have the gateway serving as the public facing remote access concentrator, this gateway is not part of the mesh community - this gateway has for its encryption domain every network at every location it can see (including its own locally connected networks).&amp;nbsp; So...when i ran the "vpn overlap_encdom" command - it had entries for every location.&amp;nbsp; Is there a correct way to resolve this?&lt;/P&gt;&lt;P&gt;All versions are 80.40 hfa91&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Feb 2021 23:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110010#M20843</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2021-02-06T23:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110012#M20844</link>
      <description>&lt;P&gt;Check below...not sure if it applies, but I would need to see it on remote session if you are willing to show me the exact issue...&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk25675" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk25675&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 00:45:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-encryption-domain/m-p/110012#M20844</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-02-07T00:45:28Z</dc:date>
    </item>
  </channel>
</rss>

