<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Routing between Domain Based and Route Based VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204854#M33992</link>
    <description>&lt;P&gt;One additional question about this topic. If there is a static route to different next hop and also for this subnet if there is a domain based route exists, how does it work Routing? Which one has more priority?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2024 04:09:55 GMT</pubDate>
    <dc:creator>starmen2000</dc:creator>
    <dc:date>2024-02-02T04:09:55Z</dc:date>
    <item>
      <title>VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204828#M33981</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I have a scenario that I need your help on!&lt;/P&gt;&lt;P&gt;I have a customer who has the following setup: (2 separate VPN communities )&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco ASA ---&amp;gt;Domain Based VPN---&amp;gt;Checkpoint---&amp;gt;Route based VPN----&amp;gt; Third party firewall&lt;/P&gt;&lt;P&gt;Users behind ASA need to talk to users behind third party firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Can routing between the two vpn communities happen ? if yes, what needs to be done at a high level ?&lt;/P&gt;&lt;P&gt;2) if the routing between vpns is happening correctly, I have a network behind 3rd party firewall that is reachable through a static route from checkpoint through an MPLS network. The desired behaviour is to use the static route through MPLS as a primary route and the routing through the route based VPN as a backup route. Can this be accomplished by assigning a lower metric to the static route that leads to MPLS and configure path monitoring to disable it if the destination network is not reachable ?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Feb 2024 22:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204828#M33981</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-01T22:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204829#M33982</link>
      <description>&lt;P&gt;There is an option for routing inside vpm community object, sounds like thats what you need.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 00:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204829#M33982</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T00:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204830#M33983</link>
      <description>&lt;P&gt;Will this work even I have two different vpn communities ? I only need to enable the vpn routing on each community ? What option to choose then ? To Center only? And what about the security rule ?&lt;/P&gt;&lt;P&gt;any insight regarding question 2 ?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 00:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204830#M33983</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-02T00:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204831#M33984</link>
      <description>&lt;P&gt;I would say center only. As far as the rule, make sure its allowed based on the traffic flow. You may need 1 rule per each community.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 00:36:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204831#M33984</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T00:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204840#M33987</link>
      <description>&lt;P&gt;For question 2, route based VPNs do routing same as if it were just an interface, so something like that ought to work if the monitoring is good. You might need to play with that and test it a few times to make sure it's reliable in all failure scenarios.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 02:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204840#M33987</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-02-02T02:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204854#M33992</link>
      <description>&lt;P&gt;One additional question about this topic. If there is a static route to different next hop and also for this subnet if there is a domain based route exists, how does it work Routing? Which one has more priority?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 04:09:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204854#M33992</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2024-02-02T04:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204855#M33993</link>
      <description>&lt;P&gt;I believe only PBR routes would take precedence over static route itself.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 04:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204855#M33993</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T04:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204856#M33994</link>
      <description>&lt;P&gt;For example there is one subject 10.16.0.0/16 internally routed to another internal router and you are using 10.16.10.0/24 subset as encryption domain for site to site domain based VPN for 3.partner. In this case would firewall domain based vpn routing work or because of static route would it not work?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 04:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204856#M33994</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2024-02-02T04:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204857#M33995</link>
      <description>&lt;P&gt;Technically, for vpn tunnel itself, you dont need to add routes manually, Now, if /16 is already there, that included range 10.16.0.1-10.16.255.254, so it should work.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 04:22:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204857#M33995</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T04:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204943#M34019</link>
      <description>&lt;P&gt;Thanks for your reply. Could you please elaborate in more details on this ? How should the security rule(s) look like ? Is there any directional match involved ? Also, should the 3rd party gateway set the subnets behind the ASA as the encryption domain for Checkpoint ?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:18:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204943#M34019</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-03T13:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204945#M34021</link>
      <description>&lt;P&gt;For route based VPN, you need to enable vpn directional match setting in global properties, I think its under vpn and then advanced (at the bottom), then in thr ule vpm culumn, you need 3 "entries", internal to vpn comm, vpn comm - vpn comm and then vpn comm to internal&lt;/P&gt;
&lt;P&gt;As far as enc domain, think of it this way...regardless if we are talking about CP, PAN, Fortinet, Cisco, Sonic Wall, makes no difference...vpn domain will ALWAYS be whatever is local behind that fw, so for 3rd party, end domain is subnet thats behind that fw, unless if its route based, then most likely empty group&lt;/P&gt;
&lt;P&gt;route based vpn -&amp;gt; vpn domain = empty group&lt;/P&gt;
&lt;P&gt;domain based vpn -&amp;gt; vpn domain = local subnet&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204945#M34021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-03T13:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204946#M34022</link>
      <description>&lt;P&gt;Thanks for your reply! but I think I misscomunicate this.&lt;/P&gt;&lt;P&gt;My actual need is to make routing between a domain based VPN and route based VPN through checkpoint.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Site A Cisco ASA ---&amp;gt;Domain Based VPN---&amp;gt;Site B Checkpoint---&amp;gt;Route based VPN----&amp;gt; Site C Third party firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The configuration you specified is only for the route based VPN setup to make the tunnel work between SiteB and SiteC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need users in Site A communicate with networks behind Site C through Checkpoint.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204946#M34022</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-03T13:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204947#M34023</link>
      <description>&lt;P&gt;Sounds like you need to enable vpn routing on domain based community.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 13:36:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204947#M34023</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-03T13:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204953#M34027</link>
      <description>&lt;P&gt;I have on last question sir. I am confused about what option to choose in vpn routing:&lt;/P&gt;&lt;P&gt;option 2 says:&amp;nbsp;To center and to other satellites through center. Use VPN routing for connection between satellites. Every packet passing from a satellite gateway to another satellite gateway is routed through the central gateway. Connection between satellite gateways and gateways that do not belong to the community are routed in the normal way.&lt;/P&gt;&lt;P&gt;option 3 says:&amp;nbsp;To center, or through the center to other satellites, to internet and other VPN targets. Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.&lt;/P&gt;&lt;P&gt;So I think that option 3 is more suitable. What do you think ? and also to confirm this setting is needed on the domain based community only since we have traffic in one direction only (from A to C through B). I am I right ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 17:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204953#M34027</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-03T17:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204954#M34028</link>
      <description>&lt;P&gt;1) You can call me Andy, Im not that old...well, 44 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;2) You did not bother me via email, its a free country, I can easily choose to ignore or delete your emails &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Yes, I would agree option you mentioned is best suitable.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 18:42:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204954#M34028</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-03T18:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204955#M34029</link>
      <description>&lt;P&gt;Thanks Andy! appreciate it!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and also to confirm this setting is needed on the domain based community only since we have traffic in one direction only (from A to C through B). I am I right ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 18:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204955#M34029</guid>
      <dc:creator>HighTech</dc:creator>
      <dc:date>2024-02-03T18:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204956#M34030</link>
      <description>&lt;P&gt;Correct. As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;had indicated, think of it this way...route based VPN tunnels utilize routing via VTI, so say for example if you have unnumbered VTI of your external interface, that would send the traffic using that interface for the tunnel. Most vendors are now abandoning domain based vpn tunnels. I believe PAN does not even let you create them any longer, Fortinet does, but literally everyone uses route based ones.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2024 19:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/204956#M34030</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-03T19:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/205003#M34040</link>
      <description>&lt;P&gt;Domain based VPN takes priority over route based.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 04:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/205003#M34040</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-02-05T04:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/240903#M40200</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/68837"&gt;@HighTech&lt;/a&gt;&amp;nbsp; can you provide feedback about ? is it Check Point able to route between domain-based-vpn and route-based-vpn ?&lt;BR /&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 14:00:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/240903#M40200</guid>
      <dc:creator>Abraminus</dc:creator>
      <dc:date>2025-02-11T14:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing between Domain Based and Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/240925#M40206</link>
      <description>&lt;P&gt;Assuming there is no conflict between the route and domain based VPN, yes.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:42:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Routing-between-Domain-Based-and-Route-Based-VPN/m-p/240925#M40206</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T15:42:01Z</dc:date>
    </item>
  </channel>
</rss>

