<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send Log to other SIEM server using site-to-site VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17346#M2932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what end is the above log entry?&lt;/P&gt;&lt;P&gt;Not clear from your description.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, having the remote end include the public IP of your gateway in their definition of the encryption domain might also help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Dec 2018 13:41:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-19T13:41:37Z</dc:date>
    <item>
      <title>Send Log to other SIEM server using site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17343#M2929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my first time using checkmate. I just want to ask some question regarding sending Syslog using LogExporter via Site-to-Site (S2S) VPN. Basically, we want to create S2S VPN with 3rd party firewall. I have done configure&amp;nbsp;interoperable device on SmartConsole. The issue is when I trying to ping from my checkpoint management to other SIEM server, the connection is drop. (You may refer my network diagram for detail). From another side, they said I advertise&amp;nbsp;my VPN tunnel using Public IP instated local subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have viewed the log from SmartView tracker and here the detail log;&lt;/P&gt;&lt;P&gt;Traffic&lt;/P&gt;&lt;P&gt;Source: y.y.y.4 (physical Public IP Gateway)&lt;/P&gt;&lt;P&gt;Destination: x1.x1.x1.10 (External Syslog Server)&lt;/P&gt;&lt;P&gt;Protocol: ICMP&lt;/P&gt;&lt;P&gt;Interface: eth1 (Public IP Port)&lt;/P&gt;&lt;P&gt;More&lt;/P&gt;&lt;P&gt;NAT additional rule number: 0&lt;/P&gt;&lt;P&gt;NAT rule number: 0&lt;/P&gt;&lt;P&gt;Xlate Src: y.y.y.5 (Virtual Public IP Gateway)&lt;/P&gt;&lt;P&gt;VPN Peer Gateway: y.1.y1.y1.2 (Public IP 3rd Party Firewall)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From 3rd party firewall side, they define my&amp;nbsp;peer local subnet as x.x.x.253 and x.x.x.200. On my VPN Domain, I have&amp;nbsp;set IP x1.x1.x1.10. Should I create manual NAT on CheckPoint or define CheckPoint Public IP as peer local subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone advise me on this?&amp;nbsp;Thank you in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2018 15:12:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17343#M2929</guid>
      <dc:creator>Aiman_Azzim</dc:creator>
      <dc:date>2018-12-18T15:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Send Log to other SIEM server using site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17344#M2930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure your VPN community has NAT disabled:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="j-img-floatstart image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76487_pastedImage_1.png" style="float: left;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 00:03:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17344#M2930</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-19T00:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Send Log to other SIEM server using site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17345#M2931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I already tick on "disable NAT inside the VPN community"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 01:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17345#M2931</guid>
      <dc:creator>Aiman_Azzim</dc:creator>
      <dc:date>2018-12-19T01:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Send Log to other SIEM server using site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17346#M2932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what end is the above log entry?&lt;/P&gt;&lt;P&gt;Not clear from your description.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any case, having the remote end include the public IP of your gateway in their definition of the encryption domain might also help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 13:41:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Send-Log-to-other-SIEM-server-using-site-to-site-VPN/m-p/17346#M2932</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-19T13:41:37Z</dc:date>
    </item>
  </channel>
</rss>

