<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote gateway (cluster) over the Internet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205947#M34177</link>
    <description>&lt;P&gt;It is and truth be told, I always sucked at it lol&lt;/P&gt;
&lt;P&gt;Personally, I would not change it myself, unless you are 100% sure what needs to be done. Probably better to verify with TAC.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 13 Feb 2024 14:52:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-13T14:52:36Z</dc:date>
    <item>
      <title>Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205923#M34172</link>
      <description>&lt;P&gt;Consider a local management- and log server (SMS) and a gateway (cluster) on location A.&lt;/P&gt;&lt;P&gt;What is best practice to setup a remote gateway (cluster) on location B,&amp;nbsp; under control of the SMS on location A.&lt;/P&gt;&lt;P&gt;Locations A and B are connected over the Internet.&lt;/P&gt;&lt;P&gt;My first thought is to setup a site-to-site IPSec VPN between the two sites and have the management traffic passing the VPN.&lt;/P&gt;&lt;P&gt;However, if the VPN fails (e.g., due to an incorrect policy installation), we also loose the management connection to location B. And there is no (easy) way to install the proper policy to get the VPN working again.&lt;/P&gt;&lt;P&gt;Should we keep the traffic between the SMS and location B outside (independent of) the VPN connection?&lt;/P&gt;&lt;P&gt;If so, I remember you must make quite a few exceptions (including manual editing of *.def files on the management server) to keep the SMS traffic outside the VPN…&lt;/P&gt;&lt;P&gt;-Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 13:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205923#M34172</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2024-02-13T13:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205930#M34173</link>
      <description>&lt;P&gt;I would say VPN would make sense onbiously, but then as you said, if it fails, you wont be able to communicate. Do you have simple diagram you can send, just to make sure Im not missing anything here.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:04:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205930#M34173</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T14:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205937#M34174</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Old school pen-and-paper &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-13 15_11_40-WhatsApp — Mozilla Firefox.jpg" style="width: 702px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24478i8C3DDFCC5C05274D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-13 15_11_40-WhatsApp — Mozilla Firefox.jpg" alt="2024-02-13 15_11_40-WhatsApp — Mozilla Firefox.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;-Frank&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205937#M34174</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2024-02-13T14:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205938#M34175</link>
      <description>&lt;P&gt;Hey, its the BEST &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;K, I think I have better picture now with what you sent. So yes, you can keep the connection between SMS and gw B separate, but Im thinking what would be best way to do this apart from VPN tunnel...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:17:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205938#M34175</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T14:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205946#M34176</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;I remember it is quite a hassle (lots of special settings and even editing some .def files on the SMS) to keep only traffic between SMS and the remote gateway (B) outside of the encrypted traffic...&lt;/P&gt;&lt;P&gt;-Frank&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205946#M34176</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2024-02-13T14:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205947#M34177</link>
      <description>&lt;P&gt;It is and truth be told, I always sucked at it lol&lt;/P&gt;
&lt;P&gt;Personally, I would not change it myself, unless you are 100% sure what needs to be done. Probably better to verify with TAC.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/205947#M34177</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T14:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Remote gateway (cluster) over the Internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/206847#M34328</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;I'm afraid TAC will not answer these questions: "did this work before", "NO", "then please go to professional services"...&lt;/P&gt;&lt;P&gt;Thanks for your help anyway. I guess it boils down to fiddling with crypt.def after all :-).&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 14:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-gateway-cluster-over-the-Internet/m-p/206847#M34328</guid>
      <dc:creator>FtW64</dc:creator>
      <dc:date>2024-02-22T14:29:38Z</dc:date>
    </item>
  </channel>
</rss>

