<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228667#M38221</link>
    <description>&lt;P&gt;Is this achievable? I mean same destination can be connected from two different firewalls as a part of encryption domain?&lt;/P&gt;</description>
    <pubDate>Tue, 01 Oct 2024 17:25:24 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2024-10-01T17:25:24Z</dc:date>
    <item>
      <title>Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228665#M38220</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;Can someone please help me with my scenario?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;I have two firewalls one in US and other is in India.&lt;/LI&gt;
&lt;LI&gt;Both the firewalls are being managed by same mgmt server which is in India.&lt;/LI&gt;
&lt;LI&gt;US firewall is managed with Public IP address&lt;/LI&gt;
&lt;LI&gt;Remote access VPNs are configured on both the firewalls having office mode pools for india is 172.16.10.0/24 and US is 172.16.8.0/24&lt;/LI&gt;
&lt;LI&gt;There is a separate VPN device in place which has a tunnel configured with say location M, eventually both the locations need to reach 10.10.10.0/24&lt;/LI&gt;
&lt;LI&gt;Now issue is even users working from home dial in US FW and India FW and they wanted to connect to servers from 10.10.10.0/24.&lt;/LI&gt;
&lt;LI&gt;I did add 10.10.10.0/24 in encryption domain so that users when they login can access the servers.&lt;/LI&gt;
&lt;LI&gt;However users when they connect to India firewall they are able to access the network without issue.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;But if the same user connect to US firewalls, they get a IP address from 172.16.8.0 office mode pool but unable to ping. When I do tracert to 10.10.10.10 it still shows India firewall as first hop and it does not route it through US firewall.&lt;/P&gt;
&lt;P&gt;I have enclosed my scenario, can someone please help me on this?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:04:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228665#M38220</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-01T17:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228667#M38221</link>
      <description>&lt;P&gt;Is this achievable? I mean same destination can be connected from two different firewalls as a part of encryption domain?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:25:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228667#M38221</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-01T17:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228668#M38222</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A hope I understood the situation. My first tip would be the Encrition domains.&lt;/P&gt;
&lt;P&gt;Did you added the&amp;nbsp;&lt;SPAN&gt;10.10.10.0/24&lt;/SPAN&gt; to both remote access ENC_DOM (UK and India)?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does SmartLog shows someting when the ping unsuccessful on US site? &lt;BR /&gt;Did you double check the Ruleset?&amp;nbsp; &lt;BR /&gt;Are there any used based rule?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228668#M38222</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-10-01T17:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228669#M38223</link>
      <description>&lt;P&gt;Yes it is added for sure and rules are added&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:35:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228669#M38223</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-01T17:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228671#M38224</link>
      <description>&lt;P&gt;And there is no user based rules? I mean that somethin is limited in the Access Role object.&lt;/P&gt;
&lt;P&gt;And Where is the&amp;nbsp;&lt;SPAN&gt;10.10.10.10&amp;nbsp;server located?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228671#M38224</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-10-01T17:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228673#M38225</link>
      <description>&lt;P&gt;Rules are there for Remote Access vpn users. 10.10.10.10 are at remote location where site-site tunels are created from US and india location but not from checkpoint firewall. I have two routers at each locations and route is added on checkpoint i.e. 10.10.10.0/24 NH 192.168.10.2 for US Location and 192.168.20.2 for India lcoation. So that when user dials in they will be routed to router and to 10.10.10.0 network&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 17:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228673#M38225</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-01T17:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228677#M38226</link>
      <description>&lt;P&gt;Interesting. Have you done a TCPdump on the US FW? Maybe you will see someting unusal.&lt;/P&gt;
&lt;P&gt;Now I'm out of ideas.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 18:21:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228677#M38226</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-10-01T18:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228690#M38227</link>
      <description>&lt;P&gt;You have overlapping VPN encryption domain for US and India firewalls. If you want to have partially, or fully overlapping VPN encryption domain, you should use MEP feature.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 20:50:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228690#M38227</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-10-01T20:50:49Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228700#M38230</link>
      <description>&lt;P&gt;Wondering MEP canbe configured for Remote access VPN?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 04:53:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228700#M38230</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-02T04:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228764#M38246</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/MEP.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 15:08:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228764#M38246</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T15:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228787#M38249</link>
      <description>&lt;P&gt;You will need to use Encryption Domains Per Community, and possibly per-peer. &amp;nbsp;You also need to have specific VPN domains for each gateway's Remote Access community. Like so:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The US gateway RA VPN domain, attached to RA community, needs to include the US site networks and the 10.10.10.0/24 network.&lt;BR /&gt;The IN gateway RA VPN domain, attached to RA community,&amp;nbsp; needs to include the IN site networks and the 10.10.10.0/24 network.&lt;/P&gt;
&lt;P&gt;The US-to-M site-to-site VPN domain needs to include the US RA-VPN pool and the US site networks.&lt;/P&gt;
&lt;P&gt;The IN-to-M site-to-site VPN domain needs to include the IN RA-VPN pool and the IN site networks.&lt;/P&gt;
&lt;P&gt;On the Site M router, the crypto ACL/VPN domain attached to the US peer, needs to include the US site and RA-VPN pool.&lt;/P&gt;
&lt;P&gt;On the Site M route,&amp;nbsp; the crypto ACL/VPN domain attached to the IN peer, needs to include the IN site and RA-VPN pool.&lt;/P&gt;
&lt;P&gt;In the access rules, you need to be sure you have sufficient rules to allow traffic flowing in all directions. &amp;nbsp;If you're not using access roles for your users, then you have extra rules to consider. &amp;nbsp;For the "legacy user access" rules, which are only attached to the RemoteAccess community, your destination column needs to include the Site M network.&lt;/P&gt;
&lt;P&gt;For the site-to-site VPN rules, your source column needs to include the IP pools of the two gateways, and the destination column include the Site M network. &amp;nbsp;You also will need a converse rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When your client connects a gateway, for Windows run "netstat -r" to make sure the client has the correct routes installed for the 10.10.10.0/24 network. &amp;nbsp;Now try your ping.&lt;/P&gt;
&lt;P&gt;FYI: until the connections are working, using tracerotue to troubleshoot a VPN will be ambiguous at best; unreliable at worst. &amp;nbsp;I would never rely on traceroute as a troubleshooting command, unfortunately. &amp;nbsp;Your best troubleshooting is the route table on the client and the logs in SmartConsole or "fw monitor" on the gateway.&lt;/P&gt;
&lt;P&gt;This configuration does work; I've done it plenty of times.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 16:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228787#M38249</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-10-02T16:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228791#M38250</link>
      <description>&lt;P&gt;This is exactly it is configured and due to overlapping encryption domain traffic is not passing through other peer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 17:32:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228791#M38250</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-10-02T17:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN for multiple Firewalls managed by same mgmt server - unable to connect</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228793#M38251</link>
      <description>&lt;P&gt;What is your overlapping encryption domain? &amp;nbsp;I'm not seeing it on the diagram you posted.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 17:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-for-multiple-Firewalls-managed-by-same-mgmt/m-p/228793#M38251</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-10-02T17:37:08Z</dc:date>
    </item>
  </channel>
</rss>

