<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Publishing an Internet service accessible through a site-to-site VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217061#M36170</link>
    <description>&lt;P&gt;You can do vpn tu list ike or vpn tu list ipsec (just type vpn tu lis (wrong spelling), but it will give all the options)&lt;/P&gt;
&lt;P&gt;Did you verify 100% that IP is indeed included in the enc domain?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2024 22:07:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-06-10T22:07:28Z</dc:date>
    <item>
      <title>Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216938#M36131</link>
      <description>&lt;P&gt;Hello everybody&lt;/P&gt;&lt;P&gt;I'm writing this post in the hope that someone has experienced the same issue. I'm trying to publish a service on the internet; the service is behind a site-to-site VPN that connects two Check Point clusters. The issue is that the request reaches the device, performs the destination NAT correctly, but the traffic is not being sent through the VPN.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the following schema could understand better the connection that i need to realize. The external ip is static.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Public Access.png" style="width: 362px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26175iCEAEAE6CA20EA08F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Public Access.png" alt="Public Access.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on this, i create the following in the Internet Firewall.&lt;/P&gt;&lt;P&gt;1. A Rule that allows communication between External IP and Public IP.&lt;/P&gt;&lt;P&gt;2. A NAT rule that converts the Public IP into Internal IP address.&lt;/P&gt;&lt;P&gt;3. In the VPN community (Both firewalls are check point managed by the same smart-1), i add the External IP address in the local domain of internet firewall.&lt;/P&gt;&lt;P&gt;4. And finally I have installed policy in the both firewalls, but the traffic doesnt go trough the VPN, that is currently working with other internal connections.&lt;/P&gt;&lt;P&gt;I have tried to perform a FW monitor and I only see the i packet, but in the smart monitor appears the initial connection from External IP to Public IP and the NATed Destination (Internal IP)&lt;/P&gt;&lt;P&gt;I think the issue is the internet firewall doesnt identify this traffic as VPN traffic&lt;/P&gt;&lt;P&gt;I dont know if i am making any mistake... any ideas?&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 13:10:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216938#M36131</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2024-06-09T13:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216939#M36132</link>
      <description>&lt;P&gt;Did you make sure encryption domains are correct?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 13:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216939#M36132</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-09T13:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216940#M36133</link>
      <description>&lt;P&gt;Yes, the VPN works correctly, I just have added the external IP in the VPN range of internet firewall with the objetive the firewall send this traffic through VPN but without successful.&lt;/P&gt;&lt;P&gt;The rest of connections in the same VPN works correctly &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 15:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216940#M36133</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2024-06-09T15:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216941#M36134</link>
      <description>&lt;P&gt;Can you send the log of the traffic you are referring to? Just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Also, see if any of below cases may apply, as I have a gut feeling they might...specially case 3&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 15:27:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/216941#M36134</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-09T15:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217021#M36154</link>
      <description>&lt;P&gt;In a domain-based VPN, the decision to encrypt is based on the &lt;EM&gt;&lt;STRONG&gt;source&lt;/STRONG&gt;&lt;/EM&gt; IP being included in the Encryption Domain.&lt;BR /&gt;Since I assume you have not included the entirety of the Internet in your encryption domain for this "Internet Gateway," it will not choose to encrypt the traffic to this external IP.&lt;BR /&gt;This is, therefore, expected behavior.&lt;/P&gt;
&lt;P&gt;A route-based VPN would probably be a better use case for this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 14:52:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217021#M36154</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T14:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217023#M36156</link>
      <description>&lt;P&gt;Hi, The external ip is always the same, i dont include the entirety of internet but I include that external IP, so the traffic should be routed trought the VPN...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 15:00:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217023#M36156</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2024-06-10T15:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217024#M36157</link>
      <description>&lt;P&gt;I see what Phoneboy is saying about route based VPN, makes sense to me. I checked this for few customer we did this for and works perfectly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 15:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217024#M36157</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-10T15:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217041#M36163</link>
      <description>&lt;P&gt;I thought people were connecting to an external IP that was translated to an internal IP.&lt;BR /&gt;Instead, it's a specific external IP that's connecting to an internal IP (via NAT)...got it.&lt;/P&gt;
&lt;P&gt;If I recall correctly, we do not include host objects in the calculation for Encryption Domain.&lt;BR /&gt;Instead of creating a host object, try creating a Network object (with a /32 subnet mask) and use that in the Encryption Domain instead.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 18:21:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217041#M36163</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T18:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217051#M36165</link>
      <description>&lt;P&gt;Yes, I know, but this VPN is part of a star community, and change this vpn mode have a high impact. If its possible i would like to solve it using the actual VPN community.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 20:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217051#M36165</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2024-06-10T20:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217054#M36168</link>
      <description>&lt;P&gt;I havent heared about it, but I have tried and still not working :(.&lt;/P&gt;&lt;P&gt;Its any way to check the negotiated SA, not the ID... I want to check somehow if the external ip added in the encyption domain is really included.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 20:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217054#M36168</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2024-06-10T20:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217061#M36170</link>
      <description>&lt;P&gt;You can do vpn tu list ike or vpn tu list ipsec (just type vpn tu lis (wrong spelling), but it will give all the options)&lt;/P&gt;
&lt;P&gt;Did you verify 100% that IP is indeed included in the enc domain?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 22:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217061#M36170</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-10T22:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing an Internet service accessible through a site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217062#M36171</link>
      <description>&lt;P&gt;Probably best to debug:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180488" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180488&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 22:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Publishing-an-Internet-service-accessible-through-a-site-to-site/m-p/217062#M36171</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T22:17:14Z</dc:date>
    </item>
  </channel>
</rss>

