<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can not access smart console over site-site VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256288#M43159</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I aimed to establish a connection to the smart console via a site-to-site VPN that is terminated on a Check Point managed by the same Check Point management server. However, I recognize that the CPMI and CPM services are accessed through implied rules. Therefore, I adhered to the documentation and commented out&lt;/P&gt;
&lt;P&gt;````&lt;/P&gt;
&lt;P&gt;/*&amp;nbsp;#define ENABLE_CPMI */&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;Since my management server is on R82 and firewalls are on R81.20, I had to comment out at below path per documentation&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;/opt/CPR8120CMP-R82/lib/implied_rules.def&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;Subsequently, a particular rule was established for CPMI and CPM services; however, I am still unable to establish a connection via site-to-site VPN.&lt;/P&gt;
&lt;P&gt;Currently, if the firewall version matches the management version lets suppose both are on R82 and I modify the $FWDIR/lib/implied_rules.def file, it functions flawlessly. However, this is not the case when the target firewall version is R81.20 or any version other than that of the management server.&lt;/P&gt;
&lt;P&gt;Has anyone noticed such an issue before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Sep 2025 07:45:46 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2025-09-01T07:45:46Z</dc:date>
    <item>
      <title>Can not access smart console over site-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256288#M43159</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I aimed to establish a connection to the smart console via a site-to-site VPN that is terminated on a Check Point managed by the same Check Point management server. However, I recognize that the CPMI and CPM services are accessed through implied rules. Therefore, I adhered to the documentation and commented out&lt;/P&gt;
&lt;P&gt;````&lt;/P&gt;
&lt;P&gt;/*&amp;nbsp;#define ENABLE_CPMI */&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;Since my management server is on R82 and firewalls are on R81.20, I had to comment out at below path per documentation&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;/opt/CPR8120CMP-R82/lib/implied_rules.def&lt;/P&gt;
&lt;P&gt;```&lt;/P&gt;
&lt;P&gt;Subsequently, a particular rule was established for CPMI and CPM services; however, I am still unable to establish a connection via site-to-site VPN.&lt;/P&gt;
&lt;P&gt;Currently, if the firewall version matches the management version lets suppose both are on R82 and I modify the $FWDIR/lib/implied_rules.def file, it functions flawlessly. However, this is not the case when the target firewall version is R81.20 or any version other than that of the management server.&lt;/P&gt;
&lt;P&gt;Has anyone noticed such an issue before?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 07:45:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256288#M43159</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2025-09-01T07:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can not access smart console over site-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256289#M43160</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Quick fix&lt;/STRONG&gt;: SSH into the Security Management and tunnel the ports 443, 18190, 19009 and 18210. Then perform a SmartConsole connect to 127.0.0.1 and you are fine as long as localhost is allowed to connect.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 08:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256289#M43160</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2025-09-01T08:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can not access smart console over site-site VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256291#M43161</link>
      <description>&lt;P&gt;Indeed - This is what I have been doing it for a long time. However, this method is effective when connecting to a single management server. The problem arises when you utilize ports 18190 and 19009 for localhost, as it prevents connections to other management servers. Given that we are overseeing multiple clients and various management servers, this is gradually becoming an impractical solution. Therefore, we established an RDP server and configured a tunnel with the customer firewalls so that we can access those directly, but we are encountering that issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 08:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-not-access-smart-console-over-site-site-VPN/m-p/256291#M43161</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2025-09-01T08:29:42Z</dc:date>
    </item>
  </channel>
</rss>

