<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clients from another LAN can't reach server from another LAN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21597#M4008</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this, and thank. I was able to update the&amp;nbsp;&lt;STRONG class="" style="color: #333333; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;$FWDIR/conf/vpn_route.conf&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;in&amp;nbsp;&lt;SPAN style="color: #333333;"&gt;the Security Management Server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I just noticed from the SmartLog, the traffic is trying to Encrypt to Global Community instead of Asia VPN Community. I want the traffic to be Encrypt/Decrypt in my Center Gateway which is fw-HongKong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 06 Jan 2019 13:25:17 GMT</pubDate>
    <dc:creator>Theo</dc:creator>
    <dc:date>2019-01-06T13:25:17Z</dc:date>
    <item>
      <title>Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21593#M4004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;I have a question about Site-Site VPN, and&amp;nbsp;my concern is that the client computers from LAN_A could not access the server from LAN_B (RDP protocol).&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;VPN Community&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Type: Star&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Name: Asia&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Center Gateways: fw-HongKong&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Satellite&amp;nbsp;Gateways: fw-Indonesia (&lt;STRONG style="border: 0px; font-weight: bold;"&gt;LAN_A&lt;/STRONG&gt;) and fw-Malaysia&amp;nbsp;&lt;SPAN style="border: 0px; font-weight: inherit;"&gt;(&lt;STRONG style="border: 0px; font-weight: bold;"&gt;LAN_B&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;VPN Routing-&amp;nbsp;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;fw-HongKong&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Gateway: Checkpoint 2200&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Version: R77.30 Build 204&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG&gt;fw-Indonesia&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Gateway: Checkpoint 1450&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Version: R77.20&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG&gt;fw-Malaysia&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Gateway: Checkpoint 1100&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Version: R77.20&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Keep in mind that above gateways are also a satellite gateways of another VPN Community (Star) which is Global. Upon checking the SmartLog, I noticed that the traffic is trying to encrypt in HQ gateway which is part of the Global Community, and is being dropped. I want to know how the traffic can be routed to the Center gateway in Asia (which is fw-HongKong) and reach the server in LAN_B which is behind fw-Malaysia gateway.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;I already added the required rule in the destination Policy but it still failing, I guess the traffic is routed to the Center gateways in Global Community? Any ideas what to check?&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Thanks for the time in reading from a newbie &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 00:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21593#M4004</guid>
      <dc:creator>Theo</dc:creator>
      <dc:date>2019-01-05T00:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21594#M4005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How specific are the encryption domains configured for each gateway, do they overlap at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is NAT enabled or disabled in each community, note more advanced configuration of the VPN routing is possible if required using vpn_route.conf.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 01:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21594#M4005</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-05T01:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21595#M4006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;note more advanced configuration of the VPN routing is possible if required using vpn_route.conf.&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;can the traffic be routed to another satellite gateway by configuring vpn_route.conf? can you please give a hint to force it? i mean is it possible that the traffic from fw-Indonesia can reach the server in fw-Malaysia by passing the Center gateway fw-HongKong?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 02:03:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21595#M4006</guid>
      <dc:creator>Theo</dc:creator>
      <dc:date>2019-01-05T02:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21596#M4007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/13928.htm#o159321" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/13928.htm#o159321"&gt;Domain Based VPN&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 02:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21596#M4007</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-05T02:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21597#M4008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got this, and thank. I was able to update the&amp;nbsp;&lt;STRONG class="" style="color: #333333; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-size: 14px; padding: 0pt;"&gt;$FWDIR/conf/vpn_route.conf&amp;nbsp;&lt;/STRONG&gt;&lt;/STRONG&gt;in&amp;nbsp;&lt;SPAN style="color: #333333;"&gt;the Security Management Server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I just noticed from the SmartLog, the traffic is trying to Encrypt to Global Community instead of Asia VPN Community. I want the traffic to be Encrypt/Decrypt in my Center Gateway which is fw-HongKong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jan 2019 13:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21597#M4008</guid>
      <dc:creator>Theo</dc:creator>
      <dc:date>2019-01-06T13:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21598#M4009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any idea guys?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 02:24:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21598#M4009</guid>
      <dc:creator>Theo</dc:creator>
      <dc:date>2019-01-11T02:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Clients from another LAN can't reach server from another LAN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21599#M4010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As above I would also check that your VPN Domains are configured specific enough to avoid overlaps. You may have to leverage the "manual" option to achieve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76954_Topology_VPN-Domain.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 02:36:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clients-from-another-LAN-can-t-reach-server-from-another-LAN/m-p/21599#M4010</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-11T02:36:51Z</dc:date>
    </item>
  </channel>
</rss>

