<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC encryption domains via Hub in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19378#M3577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;simply add 10.200.0.0/16 into the HUB EncDom &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Nov 2018 09:18:47 GMT</pubDate>
    <dc:creator>Jerry</dc:creator>
    <dc:date>2018-11-22T09:18:47Z</dc:date>
    <item>
      <title>IPSEC encryption domains via Hub</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19377#M3576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our customer has several &lt;EM&gt;meshed&lt;/EM&gt; VPN Communities, connecting his HQ with remote sites as well as with suppliers. Situation is as follows for 3 sites:&lt;/P&gt;&lt;P&gt;A (Supplier - Juniper) &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;B (HQ CP5000)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;C (RemoteSite CP14x0)&lt;BR /&gt;10.10.0.0/24 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.200.10.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.200.201.0/24&lt;BR /&gt;10.20.0.0/16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.200.11.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.200.202.0/24&lt;BR /&gt;10.40.0.0/16&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.200.12.0/24&lt;/P&gt;&lt;P&gt;10.0.0.0/8&lt;/P&gt;&lt;P&gt;Policy-based s2s between A and B.&lt;/P&gt;&lt;P&gt;Route-based s2s between B and C.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users in Site C 10.200.201.0/24 (customer remote site) need to connect to a supplier's server in 10.40.0.0/16. This traffic is allowed and working - my predecessor configured user.def.FW1 for the tunnel between A and B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, due to changes and the supplier being reluctant to configure lots of encryption domains , we were looking into changing themfor the tunnel between A and B. Plan was to set it as follows for our side:&lt;/P&gt;&lt;P&gt;B&lt;/P&gt;&lt;P&gt;10.200.0.0/16&lt;/P&gt;&lt;P&gt;But then traffic between C and A stopped working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally my question:&lt;/P&gt;&lt;P&gt;How can we change B's encryption domain to include C's subnets?&amp;nbsp;Note that also customer does not allow hide NAT because he fears this might interfere with H323 video traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 07:59:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19377#M3576</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2018-11-22T07:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC encryption domains via Hub</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19378#M3577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;simply add 10.200.0.0/16 into the HUB EncDom &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 09:18:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19378#M3577</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-11-22T09:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC encryption domains via Hub</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19379#M3578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Indeed, we did. But then traffic between C and A didn't pass anymore ("packet shouldn't have been decrypted").&lt;/P&gt;&lt;P&gt;Going to have to dig into the user.def.FW1 file I think.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 12:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19379#M3578</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2018-11-22T12:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC encryption domains via Hub</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19380#M3579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what about appropiate (respective) routing is in place Philip ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 12:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPSEC-encryption-domains-via-Hub/m-p/19380#M3579</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-11-22T12:59:48Z</dc:date>
    </item>
  </channel>
</rss>

