<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain-Based VPN with Dynamic Routing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17102#M2871</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our customer got 2 sites with on-premise clusters running VPNs to bunch of CloudGaurd clusters hosted on Azure/AWS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My predecessor chose to configure MEP for fail-over between the on-premise clusters.&lt;/P&gt;&lt;P&gt;However, in a fail-over scenario all the users are still routed&amp;nbsp;(static routing being to date) through the primary site and causing asymmetric routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is&amp;nbsp;run dynamic routing to fail-over automatically the public clouds connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue currently is the domain-based VPN which always prefers VPN kernel routes and the idea is to control how traffic is routed to the public cloud using BGP (CORE switches &amp;lt;--BGP--&amp;gt; On-Premise clusters&amp;nbsp;&lt;SPAN&gt;&amp;lt;--BGP--&amp;gt; Public Cloud Clusters).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route-based VPN will resolve it as well but will introduce another challenges like narrowing down the encryption domains while we have another Domain-Based VPNs with 3rd parties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess we'll have some healthy debates after xmas whether to go ahead with disabling&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;reroute_encrypted_packets&lt;SPAN&gt;&amp;nbsp;or converting everything to&amp;nbsp;&lt;SPAN style="color: #3d3d3d;"&gt;Route-based VPN.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Cheers!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Dec 2018 19:21:54 GMT</pubDate>
    <dc:creator>Alex_Shpilman</dc:creator>
    <dc:date>2018-12-20T19:21:54Z</dc:date>
    <item>
      <title>Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17094#M2863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to investigate if it's possible to stop the VPN routes propagation with Domain-Based VPN&amp;nbsp; in a order to control the routing with BGP.&lt;/P&gt;&lt;P&gt;Migrating to Route-Based is an option but has it's limitations when running a mixture of Route-Based VPN with Domain-Based VPN (as per&amp;nbsp;sk109340).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a valid solution to disable "&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;reroute_encrypted_packets" on the relevant gateways using GuiDBedit?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;Any other ideas how it can be achieved?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 01:51:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17094#M2863</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2018-12-18T01:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17095#M2864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you saying the routes from the VPN propagate to BGP or vice versa?&lt;/P&gt;&lt;P&gt;Perhaps you can filter with routemaps:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100501" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100501"&gt;How to configure Routemaps in Gaia Clish&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17095#M2864</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-19T00:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17096#M2865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I use BGP on top of a&amp;nbsp;&amp;nbsp;domain-based VPN, the gateway always prefers the VPN routes. I am trying to find a way to stop the VPN routes to be propagated automatically so Gaia routing can be used instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the amount of existing VPN communities this is a bit painful to transition to route-based VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17096#M2865</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2018-12-19T00:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17097#M2866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not an issue of the routes propagating to BGP, it's an issue of the gateway preferring VPN routes, which are basically happening in the kernel.&lt;/P&gt;&lt;P&gt;Got it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Having read the SK you referenced, I would come to the same conclusion: change the reroute_encrypted_packets setting.&lt;/P&gt;&lt;P&gt;I also see&amp;nbsp;you have a TAC case and that we're checking on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17097#M2866</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-19T00:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17098#M2867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch-Abernathy&lt;/A&gt;‌,&amp;nbsp;I just needed an assurance that this is a valid solution and will be supported by the TAC in case of any issues.&lt;/P&gt;&lt;P&gt;I didn't raise a TAC case (yet) but ran it passed our local SE, so perhaps he opened one on my behalf.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17098#M2867</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2018-12-19T00:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17099#M2868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Misspoke on the TAC case, but your SE is definitely asking around &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17099#M2868</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-19T00:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17100#M2869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just an update, I tested this scenario in the lab and disabling&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;reroute_encrypted_packets&lt;SPAN&gt;&amp;nbsp;works like a charm. The kernel VPN routes are still there but not being used to forward traffic, OS routing is being used instead.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 11:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17100#M2869</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2018-12-20T11:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17101#M2870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad it works.&lt;/P&gt;&lt;P&gt;I'm curious what your exact use case is here (i.e. why you want to override the VPN routes with BGP).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 15:45:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17101#M2870</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-20T15:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17102#M2871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our customer got 2 sites with on-premise clusters running VPNs to bunch of CloudGaurd clusters hosted on Azure/AWS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My predecessor chose to configure MEP for fail-over between the on-premise clusters.&lt;/P&gt;&lt;P&gt;However, in a fail-over scenario all the users are still routed&amp;nbsp;(static routing being to date) through the primary site and causing asymmetric routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is&amp;nbsp;run dynamic routing to fail-over automatically the public clouds connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue currently is the domain-based VPN which always prefers VPN kernel routes and the idea is to control how traffic is routed to the public cloud using BGP (CORE switches &amp;lt;--BGP--&amp;gt; On-Premise clusters&amp;nbsp;&lt;SPAN&gt;&amp;lt;--BGP--&amp;gt; Public Cloud Clusters).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route-based VPN will resolve it as well but will introduce another challenges like narrowing down the encryption domains while we have another Domain-Based VPNs with 3rd parties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess we'll have some healthy debates after xmas whether to go ahead with disabling&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;reroute_encrypted_packets&lt;SPAN&gt;&amp;nbsp;or converting everything to&amp;nbsp;&lt;SPAN style="color: #3d3d3d;"&gt;Route-based VPN.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN style="color: #3d3d3d;"&gt;Cheers!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 19:21:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/17102#M2871</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2018-12-20T19:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/59167#M11928</link>
      <description>&lt;P&gt;I have just stumbled across this post, and am curious to know the final outcome as i´m in a similar situation. Was disabling&amp;nbsp;&lt;SPAN&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;reroute_encrypted_packets&lt;/FONT&gt; a valid option? Or did you choose to migrate to route-based vpn?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 14:24:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/59167#M11928</guid>
      <dc:creator>Rick_Ther</dc:creator>
      <dc:date>2019-07-29T14:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/65608#M13406</link>
      <description>&lt;P&gt;Sorry about the late response, just saw it now.&lt;/P&gt;&lt;P&gt;After many delays we're migrating to route-based VPN very soon.&lt;/P&gt;&lt;P&gt;I did some further testing and couldn't achieve the desired outcome with domain-based VPN, with route-based VPN it's a very painful migration but we'll get there.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 21:40:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/65608#M13406</guid>
      <dc:creator>Alex_Shpilman</dc:creator>
      <dc:date>2019-10-22T21:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Domain-Based VPN with Dynamic Routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/65691#M13421</link>
      <description>&lt;P&gt;Np. Ok, thx for the feedback.&lt;/P&gt;&lt;P&gt;Once you are done, I would appreciate the opportunity to hear how your migration to route based VPN went (pitfalls, unexpected limitations, etc.) . Personally, when I compare route based VPN to domain based VPN, I do not see any (technical) pro points for domain based VPN. Domain based VPNs&amp;nbsp;are way to inflexible.&lt;/P&gt;&lt;P&gt;When all the limitations for route based VPNs are lifted in R80.xx I am curious to know how many migrations to route based VPN will takes place&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 15:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-Based-VPN-with-Dynamic-Routing/m-p/65691#M13421</guid>
      <dc:creator>Rick_Ther</dc:creator>
      <dc:date>2019-10-23T15:57:46Z</dc:date>
    </item>
  </channel>
</rss>

