<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN with overlapping subnet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137075#M24470</link>
    <description>&lt;P&gt;NAT or change the Remote A subnet&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 11:55:57 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-12-23T11:55:57Z</dc:date>
    <item>
      <title>Site to Site VPN with overlapping subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137067#M24468</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing some issue with overlapping subnet, hope to be able to get some solution from this forums.&lt;/P&gt;&lt;P&gt;Below are what we current having / using&lt;/P&gt;&lt;P&gt;Star topology VPN&lt;/P&gt;&lt;P&gt;Main Site (Checkpoint) - 10.0.0.0/24&lt;/P&gt;&lt;P&gt;Remote Site A (Checkpoint)- 192.168.2.0/24, 192.168.3.0/24 (Configured IPSec Tunnel)&lt;/P&gt;&lt;P&gt;Remote Site B (Fortinet) - 192.168.0.0/21 (Having issue configuring IPSec Tunnel)&lt;/P&gt;&lt;P&gt;I am having issue trying to establish a IPSec Tunnel with remote site B, most likely due to the overlapping of subnet.&lt;/P&gt;&lt;P&gt;I would like to seek for advise on how can we move forward to solve this issue.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 10:47:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137067#M24468</guid>
      <dc:creator>gavin211</dc:creator>
      <dc:date>2021-12-23T10:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with overlapping subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137075#M24470</link>
      <description>&lt;P&gt;NAT or change the Remote A subnet&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 11:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137075#M24470</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-23T11:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with overlapping subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137079#M24473</link>
      <description>&lt;P&gt;Changing remote A subnet will not be possible. Is there a guide for NAT between site to site VPN?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 12:06:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137079#M24473</guid>
      <dc:creator>gavin211</dc:creator>
      <dc:date>2021-12-23T12:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with overlapping subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137084#M24476</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;is absolutely right. Now, personally, and this is just me, what I would do, just to be sure is maybe do quick vpn debug on CP side to confirm, but yea, it appears overlapping subnets are problem, for sure. 192.168.0.0/21 would definitely encompass 192.168.2.0/24 network. You can run below command on CP firewall and see what it shows.&lt;/P&gt;
&lt;P&gt;vpn overlap_encdom&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 12:51:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137084#M24476</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-23T12:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with overlapping subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137087#M24478</link>
      <description>&lt;P&gt;This is a classic case, for every vendor running IPSec VPN S2S tunnels. There are plenty explanations on how to fix it with NAT. For example,&amp;nbsp;&lt;A href="https://www.practicalnetworking.net/stand-alone/vpn-overlapping-networks/" target="_blank"&gt;https://www.practicalnetworking.net/stand-alone/vpn-overlapping-networks/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 13:15:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-with-overlapping-subnet/m-p/137087#M24478</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-23T13:15:32Z</dc:date>
    </item>
  </channel>
</rss>

