<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195685#M32809</link>
    <description>&lt;P&gt;Version/JHF in use?&lt;BR /&gt;All clusters are managed by the same management?&lt;BR /&gt;Not sure why you need three different VPN communities here when a single one should suffice.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2023 20:35:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-10-19T20:35:41Z</dc:date>
    <item>
      <title>VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195633#M32803</link>
      <description>&lt;P&gt;Hello everyone!&lt;BR /&gt;I need your help...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have 3 different FW clusters on my network, on different sites, let's call them&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster 1 at site 1 (holds network A)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster 2 at site 2 (holds network B)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster 3 at site 3 (holds network C)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;while each of them is responsible for a network&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;10.0.0.0/24 &lt;SPAN&gt;Network A&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;20.0.0.0/24 &lt;SPAN&gt;Network B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;30.0.0.0/24 &lt;SPAN&gt;Network C&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I point out that in each of the sites where there is a cluster, the FW also has legs for the benefit of the other networks, for users of these networks who are on these sites&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In addition to this I have several small satellite sites where there are users who will connect to any of my networks&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I created 3 VPN Community between the relevant satellite sites and the clusters in a star configuration, for the benefit of each of the networks&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That is, I have 3 VPN Communities, each of which has a different cluster that is defined as a Center and a number of small FWs that are defined as satellites&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The sites themselves have an encryption domain that contains all the networks that exist on the site&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is my existing situation, now I will explain the problem&lt;/SPAN&gt;...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I am at a satellite site sending a ping from a computer located on network A to a computer at another satellite site on the same network (A), I expect the traffic to go through cluster 1 that holds network A, and from there to the other satellite site&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What actually happens is that when I send a ping from one satellite site on network A to another site on network A, I recognize that the traffic goes through cluster 2, for example, which serves as a center for VPN Community that is not relevant to network A&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I saw that there is an option to define in the Rule itself which VPN it will be associated with, I tried it and the situation did not change&lt;/SPAN&gt;.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Is this the normal situation&lt;/SPAN&gt;?&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If this is not a normal situation, what do I need to change / specify in order for it to be resolved&lt;/SPAN&gt;?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would appreciate your advice&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 13:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195633#M32803</guid>
      <dc:creator>michaelsharet</dc:creator>
      <dc:date>2023-10-19T13:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195685#M32809</link>
      <description>&lt;P&gt;Version/JHF in use?&lt;BR /&gt;All clusters are managed by the same management?&lt;BR /&gt;Not sure why you need three different VPN communities here when a single one should suffice.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 20:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195685#M32809</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-19T20:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195831#M32824</link>
      <description>&lt;P&gt;Hi good morning,&lt;BR /&gt;All managed through one management in version R81.10&amp;nbsp;&lt;BR /&gt;My clusters are version 81, and various versions of GHF.&lt;/P&gt;&lt;P&gt;Could you explain to me in more detail why 3 different VPNs for my case are not necessary, and why it is better to make one?&lt;/P&gt;&lt;P&gt;I mention again, I have 3 different networks that I want full partitioning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your response&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 06:50:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195831#M32824</guid>
      <dc:creator>michaelsharet</dc:creator>
      <dc:date>2023-10-22T06:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195838#M32826</link>
      <description>&lt;P&gt;Because it is only more work but no better result. See &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Check-Point-VPN.htm?tocpath=Check%20Point%20VPN%7C_____0#Check_Point_VPN" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Check-Point-VPN.htm?tocpath=Check%20Point%20VPN%7C_____0#Check_Point_VPN&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 09:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195838#M32826</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-22T09:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195840#M32827</link>
      <description>&lt;P&gt;So if I understand you correctly, I need to create one VPN C in which I have the 3 clusters in the center and all the other small remote sites in the satellites? And this way I get the same result as I have today?&lt;/P&gt;&lt;P&gt;And what about my question is it supposed to work like this? Every small website when looking for a certain network should not go directly to the cluster that owns that network?&lt;/P&gt;&lt;P&gt;What you are proposing is only an "improvement" of the situation I have today... I want to understand if it is normal and how it can be adjusted if not&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 11:35:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195840#M32827</guid>
      <dc:creator>michaelsharet</dc:creator>
      <dc:date>2023-10-22T11:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195864#M32828</link>
      <description>&lt;P&gt;This is what you need to do. Create ONE star community, with clusters as center gateways, others as satellite and adjust below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;DIV id="tinyMceEditor_34bbb6791b9389the_rock_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_34bbb6791b9389the_rock_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22912i5F9349308F9A0EC1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22913iDE2DCFDE90BB2125/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 18:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195864#M32828</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-22T18:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195942#M32840</link>
      <description>&lt;P&gt;I believe it is your current configuration that is causing the behavior you're seeing.&lt;BR /&gt;It should disappear when you move to a single VPN Community (properly configured of course).&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 17:32:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195942#M32840</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-23T17:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195995#M32847</link>
      <description>&lt;P&gt;I do not understand your questions as they are covered in referenced admin guide. Did you study the Admin guide well ? &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Check-Point-VPN.htm?tocpath=Check%20Point%20VPN%7C_____0#Check_Point_VPN" target="_blank" rel="noopener noreferrer"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Con...&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 07:23:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN/m-p/195995#M32847</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-24T07:23:36Z</dc:date>
    </item>
  </channel>
</rss>

