<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic is suddenly encrypted by VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192396#M32231</link>
    <description>&lt;P&gt;Yea...so that message packet should not have been decrypted really means it SHOULD have been encrypted, ie firewall "thinks" it should go through VPN.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2023 11:36:07 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-09-12T11:36:07Z</dc:date>
    <item>
      <title>Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192015#M32167</link>
      <description>&lt;P&gt;Hello Checkpoint Community,&lt;BR /&gt;&lt;BR /&gt;We have this unusual behavior in our client's instance wherein traffic is suddenly encrypted through VPN when it shouldn't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-09-08 171507.png" style="width: 904px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22390i31076369241E31B8/image-dimensions/904x102?v=v2" width="904" height="102" role="button" title="Screenshot 2023-09-08 171507.png" alt="Screenshot 2023-09-08 171507.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We honestly don't know why this happened, as there were no changes performed.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;Does anyone have any experience in this and could give us some insight.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 09:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192015#M32167</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-08T09:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192091#M32181</link>
      <description>&lt;P&gt;Do you have a route-based VPN (with VTIs) configured here?&lt;BR /&gt;You'd probably need to dig into the log entries (the full log cards) to see why the rulebase logic changed.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 02:28:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192091#M32181</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-09T02:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192214#M32204</link>
      <description>&lt;P&gt;When opening the log cards, it just says that it's encrypted. But yeah I do think I have a route-based VPN.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I do noticed that in the log card, the traffic is routed to an IPsec VPN peer for some reason, which shouldn't be the case since I didn't define any routes that would do such action.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 13:29:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192214#M32204</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-11T13:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192233#M32212</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The VPN log mentions tcp-high-ports as the service and the non-VPN log mentions TCP-9001 as the service. Can you check on what rule the VPN is hit? And check on what rule it should hit?&lt;BR /&gt;&lt;BR /&gt;Did you changed 'Match for Any' in the mentioned services so traffic is hitting another rule than expected?&lt;BR /&gt;&lt;BR /&gt;Maybe you can take a look at the Audit log to see what was changed after September 6th.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 14:26:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192233#M32212</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2023-09-11T14:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192236#M32213</link>
      <description>&lt;P&gt;I see the point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;is making, I would definitely check into that as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 14:43:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192236#M32213</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T14:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192274#M32218</link>
      <description>&lt;P&gt;Is it all static routes or are dynamic routes used?&lt;BR /&gt;Either way, it appears that routing changed somewhere.&lt;BR /&gt;This would probably require investigation from the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192274#M32218</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-11T17:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192353#M32226</link>
      <description>&lt;P&gt;You can also follow&amp;nbsp;sk25675 and&amp;nbsp;&lt;SPAN&gt;sk98241 to exclude traffic from being encrypted.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 23:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192353#M32226</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-09-11T23:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192363#M32227</link>
      <description>&lt;P&gt;Definitely good SKs.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 00:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192363#M32227</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-12T00:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192383#M32228</link>
      <description>&lt;P&gt;I will check this as soon as I'm on site tomorrow. But I do remember its "Match Any".&lt;BR /&gt;&lt;BR /&gt;There's no changes to the rule as well.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 09:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192383#M32228</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-12T09:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192385#M32229</link>
      <description>&lt;P&gt;Hello Everyone,&lt;BR /&gt;&lt;BR /&gt;To add, I just found a blocked rule regarding this which is unusual. It shouldn't be communicating to my other NGFW pair but it seems it is (via VPN)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 960px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22426iACCB54565D6529EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm currently checking the SKs provided by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28648"&gt;@Zolocofxp&lt;/a&gt;, while checking&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;'s suggestion&lt;BR /&gt;&lt;BR /&gt;Will update you guys once there's improvements. Thank you so much for the help.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 09:31:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192385#M32229</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-12T09:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192396#M32231</link>
      <description>&lt;P&gt;Yea...so that message packet should not have been decrypted really means it SHOULD have been encrypted, ie firewall "thinks" it should go through VPN.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 11:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192396#M32231</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-12T11:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192471#M32248</link>
      <description>&lt;P&gt;I actually found a reason as to why this happened. There's overlapping internal domains in both of my clusters, and unfortunately this traffic is being routed towards the other Firewall (NGFW Pair 1) instead. The correct behavior should be that it's going to be routed to its own Firewall (NGFW Pair 2). This has been now addressed.&lt;BR /&gt;&lt;BR /&gt;Anyways, I created a policy to address this, and everything works smoothly now. I might have created a not-so-specific policy and that's why for some reason it keeps on routing the traffic to NGFW Pair 1.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 04:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192471#M32248</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-13T04:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192472#M32249</link>
      <description>&lt;P&gt;Thank you guys, I was able to troubleshoot it with the help of your inputs. Everything's working as intended now.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 04:15:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192472#M32249</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2023-09-13T04:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic is suddenly encrypted by VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192518#M32256</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 11:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-is-suddenly-encrypted-by-VPN/m-p/192518#M32256</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-13T11:26:26Z</dc:date>
    </item>
  </channel>
</rss>

