<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude CPM Traffic from Implied Rules for one GW r81.10 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187862#M31472</link>
    <description>&lt;P&gt;I agree with you, but there is only one cluster of gateways and there is only one public address (the vip address is public, and the addresses on the nodes are local), so it is not possible to manage them outside the tunnel.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jul 2023 13:10:33 GMT</pubDate>
    <dc:creator>Andrey_Gl</dc:creator>
    <dc:date>2023-07-27T13:10:33Z</dc:date>
    <item>
      <title>Exclude CPM Traffic from Implied Rules for one GW r81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187827#M31455</link>
      <description>&lt;P&gt;We manage a lot of gateways through our SMS, but on one gateway there is a need to encypt management traffic (CPM, etc.) through a tunnel. How can we configure the implied_rules.def file so that the traffic specifically to that gateway does&amp;nbsp; go through the tunnel but not for others?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:24:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187827#M31455</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-07-27T11:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude CPM Traffic from Implied Rules for one GW r81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187829#M31456</link>
      <description>&lt;P&gt;Please look at:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187#M1452" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Exclude-CPM-Traffic-from-Implied-Rules/m-p/9187#M1452&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sk105719&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;CPMI/CPM traffic from remote SmartConsole client to the Management Server is not encrypted, but accepted by Implied Rules instead:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105719" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105719&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But as PhoneBoy wrote:&lt;/P&gt;
&lt;P&gt;"As a general rule, it is a bad idea to force control connections through the VPN.&lt;/P&gt;
&lt;P&gt;If your VPN goes down for any reason, getting it back up when you have no ability to manage the gateway becomes a challenge."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:54:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187829#M31456</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2023-07-27T11:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude CPM Traffic from Implied Rules for one GW r81.10</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187862#M31472</link>
      <description>&lt;P&gt;I agree with you, but there is only one cluster of gateways and there is only one public address (the vip address is public, and the addresses on the nodes are local), so it is not possible to manage them outside the tunnel.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 13:10:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Exclude-CPM-Traffic-from-Implied-Rules-for-one-GW-r81-10/m-p/187862#M31472</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-07-27T13:10:33Z</dc:date>
    </item>
  </channel>
</rss>

