<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint VPN Domain Supernetting Questions in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168295#M27996</link>
    <description>&lt;P&gt;The VPN tunnel is working but the supernetting is not working as what I expected. The largest subnet 10.105.0.0/16 is defined inside the VPN domain but CheckPoint is supernet it to 10.105.0.0/17. Please correct me if I was wrong about the supernet&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 01:18:11 GMT</pubDate>
    <dc:creator>JLo</dc:creator>
    <dc:date>2023-01-19T01:18:11Z</dc:date>
    <item>
      <title>CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168157#M27972</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about the CheckPoint VPN domain supernetting feature. Recently my side have a VPN tunnel established between CheckPoint and Fortigate firewall.&lt;/P&gt;&lt;P&gt;- CheckPoint's VPN domains as below,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;10.100.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.102.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.103.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.0.0/16&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.53.0/24&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.205.0/24&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.106.201.0/28&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.106.216.0/24&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.19.44&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.21.161/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.86.119/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.88.142/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.92.80/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.95.83/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.104.180.26/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.12.59/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.16.10/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.33.37/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.53.7x/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.105.181.x/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;10.106.115.32/32&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;- Fortigate VPN domain can found inside the attachment.&lt;/P&gt;&lt;P&gt;- I did vpn and ike debug on the CheckPoint gateway and found that the VPN domain superNet using &lt;A href="http://10.105.0.0/17" target="_blank" rel="noopener"&gt;10.105.0.0/17&lt;/A&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;My question is why&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;CheckPoint chooses&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://10.105.0.0/17" target="_blank" rel="noopener"&gt;10.105.0.0/17&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;and not the other segment to SuperNet&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;1. Why do CheckPoint supernet to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://10.105.0.0/17" target="_blank" rel="noopener"&gt;10.105.0.0/17&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(we do not define this as one of the Traffic Selectors on CheckPoint) and not the other segment such as&lt;/DIV&gt;&lt;DIV&gt;a.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://10.105.0.0/16" target="_blank" rel="noopener"&gt;10.105.0.0/16&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(we defined this as one of the Traffic Selector)&lt;/DIV&gt;&lt;DIV&gt;b.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://10.105.0.0/18" target="_blank" rel="noopener"&gt;10.105.0.0/18&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(we do not have this as one of the Traffic Selector)&lt;/DIV&gt;&lt;DIV&gt;c.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://10.105.0.0/15" target="_blank" rel="noopener"&gt;10.105.0.0/15&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(we do not have have this as one of the Traffic Selector)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Hope anyone can answer this. Thank you&lt;/DIV&gt;</description>
      <pubDate>Wed, 18 Jan 2023 04:09:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168157#M27972</guid>
      <dc:creator>JLo</dc:creator>
      <dc:date>2023-01-18T04:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168174#M27975</link>
      <description>&lt;P&gt;Why your question about the why of supernetting ? Does the VPN tunnel work as expected or not ?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 09:54:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168174#M27975</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-01-18T09:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168252#M27985</link>
      <description>&lt;P&gt;This doesn't seem like it's supernetting correctly since you explicitly list 10.105.0.0/16 in your Encryption Domain.&lt;BR /&gt;It shouldn't even create a 10.105.0.0/17 route in this case.&lt;BR /&gt;Recommend engaging with the TAC here.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 16:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168252#M27985</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-18T16:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168294#M27995</link>
      <description>&lt;P&gt;I also thinking the supernetting is no working correctly. Will try engage with TAC first for this problem.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 01:15:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168294#M27995</guid>
      <dc:creator>JLo</dc:creator>
      <dc:date>2023-01-19T01:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168295#M27996</link>
      <description>&lt;P&gt;The VPN tunnel is working but the supernetting is not working as what I expected. The largest subnet 10.105.0.0/16 is defined inside the VPN domain but CheckPoint is supernet it to 10.105.0.0/17. Please correct me if I was wrong about the supernet&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 01:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/168295#M27996</guid>
      <dc:creator>JLo</dc:creator>
      <dc:date>2023-01-19T01:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint VPN Domain Supernetting Questions</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/173360#M28938</link>
      <description>&lt;P&gt;Did TAC help to resolve this ?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CheckPoint-VPN-Domain-Supernetting-Questions/m-p/173360#M28938</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-02T13:16:06Z</dc:date>
    </item>
  </channel>
</rss>

