<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 VPN's Same Remote Encryption Domain in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208014#M34472</link>
    <description>&lt;P&gt;Configuration seems valid.&lt;/P&gt;
&lt;P&gt;Checkpoint GW knows to return the traffic to the vpn peer the original conn was received through.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Mar 2024 22:44:18 GMT</pubDate>
    <dc:creator>AmirArama</dc:creator>
    <dc:date>2024-03-06T22:44:18Z</dc:date>
    <item>
      <title>2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208000#M34468</link>
      <description>&lt;P&gt;I have been tasked with creating two VPN connections to a new vendor, a backup and a primary.&amp;nbsp; Each has a different peer IP but the catch is the encryption domain will be the same on both.&lt;/P&gt;
&lt;P&gt;I am not clear yet if both VPN connections will be up all of the time or not (I don't know if they are using probing, or DPD, or something that will keep phase 1 and 2 up).&lt;/P&gt;
&lt;P&gt;To meet this requirement is it valid for me to configure one VPN star community and have both of the vendor's Satellite Gateways in the community like in the screen shot?&amp;nbsp; Everything except the peer IP's is the same, encryption, lifetimes, etc.&lt;/P&gt;
&lt;P&gt;The production traffic traversing the VPN will always be initiated from the remote end.&lt;/P&gt;
&lt;P&gt;Will Check Point be able to route through the appropriate VPN by knowing which one received the traffic?&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 18:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208000#M34468</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-03-06T18:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208014#M34472</link>
      <description>&lt;P&gt;Configuration seems valid.&lt;/P&gt;
&lt;P&gt;Checkpoint GW knows to return the traffic to the vpn peer the original conn was received through.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 22:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208014#M34472</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-06T22:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208019#M34473</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;&amp;nbsp;, seems right to me as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 00:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208019#M34473</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-07T00:00:41Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208099#M34481</link>
      <description>&lt;P&gt;My understanding is that you can't have identical encryption domains for 2 different peers. Does putting them in a star VPN topology get around that? I would be under the impression that NAT would need to be involved for this scenario.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208099#M34481</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-03-07T14:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208100#M34482</link>
      <description>&lt;P&gt;You mean same enc. domain for different interoperable objects? If so, definitely you can, I did that in the lab many times and worked fine.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208100#M34482</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-07T14:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208106#M34483</link>
      <description>&lt;P&gt;Correct. Interesting... just trying to wrap my head around how that works.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Interoperable Object 1 - 1.1.1.1 with the encryption domain of 192.168.4.0/24&lt;/LI&gt;&lt;LI&gt;Interoperable Object 2 - 2.2.2.2&amp;nbsp;with the encryption domain of 192.168.4.0/24&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Both peers have a webserver using the IP 192.168.4.25. How does my device get to the proper webserver?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:46:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208106#M34483</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-03-07T14:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208107#M34484</link>
      <description>&lt;P&gt;putting identical enc domain on the two or more vpn peers or what called implicit MEP indeed require static nat usually in case both VPN peers forwarding the traffic to the same network and it needs to know from which gw to return.&lt;/P&gt;
&lt;P&gt;in this case the one of the vpn peers only initiate the traffic to the other side, and in this case it doesn't require a nat, and the CP GW knows to return the return traffic to the original vpn peer&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:48:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208107#M34484</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-07T14:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208108#M34485</link>
      <description>&lt;P&gt;I see now what you meant&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp;. For instance like that, yea, sounds like NAT would be needed.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:48:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208108#M34485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-07T14:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208109#M34486</link>
      <description>&lt;P&gt;In my scenario there will be two VPN's to two different peers and the same server IP at the end of each, however only 1 VPN will have the active server at a time.&amp;nbsp; Traffic to / from the server IP will not traverse both VPN's at the same time.&amp;nbsp; Does this still require MEP?&lt;/P&gt;
&lt;P&gt;It's a primary and backup VPN.&lt;/P&gt;
&lt;P&gt;Unfortunately I don't think NAT is an option in my scenario.&lt;/P&gt;
&lt;P&gt;I built out the scenario in my lab yesterday and it seems to work.&amp;nbsp; Moving the server from behind VPN 1 to behind VPN 2 on the fly is a little rough, it's like a timeout needs to occur.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will test more before trying in production.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208109#M34486</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-03-07T14:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208112#M34487</link>
      <description>&lt;P&gt;Correct me if Im mistaken when I say this&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;&amp;nbsp;, but I believe from smart console in vpn community, mep setting there ONLY applies to explicit mep, not implicit?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;At least thats what it looks like from below link...&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 14:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208112#M34487</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-07T14:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208114#M34488</link>
      <description>&lt;P&gt;How would I do the static NAT.&amp;nbsp; I need the same remote IP presented to the server inside my network?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 15:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208114#M34488</guid>
      <dc:creator>Mike_Jensen</dc:creator>
      <dc:date>2024-03-07T15:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208115#M34489</link>
      <description>&lt;P&gt;That makes sense, thank you for clarifying!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 15:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208115#M34489</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-03-07T15:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: 2 VPN's Same Remote Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208117#M34490</link>
      <description>&lt;P&gt;implicit MEP is the description of having the same enc domain on multiple vpn peers. it doesn't mean that you need to explicitly configure MEP in the VPN community (which called explicit MEP).&lt;/P&gt;
&lt;P&gt;in case you need to initiate traffic from your side to the server IP located behind each of the remote GWs (and the server have two paths to reach your network via both GWs), how would the server know through which it should return to keep the symmetry? (assuming they care about symmetry on the other side) you will need to configure source NAT (hide behind IP or GW) on the remote GWs, so the server will get the packet from the GW address, and since it needs to reply to this IP, the symmetry will be kept. if you have other trick to keep the symmetry for return, you don't need SNAT.&lt;/P&gt;
&lt;P&gt;read more here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in case all the traffic only initiated from the remote server side, then you don't need NAT at all. the server will go from one of the GWs to your GW, and your GW will return it to the same original VPN peer (related to that connection).&lt;/P&gt;
&lt;P&gt;moving existing connection on the fly may probably die because of stateful inspection on the remote side GWs or that the connection is registered under Peer1 on your local GW.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 15:27:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/m-p/208117#M34490</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-07T15:27:14Z</dc:date>
    </item>
  </channel>
</rss>

