<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confused about VPN Routing Options in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28494#M5792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good explain so many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2018 06:37:55 GMT</pubDate>
    <dc:creator>Worapong_Janloy</dc:creator>
    <dc:date>2018-09-21T06:37:55Z</dc:date>
    <item>
      <title>Confused about VPN Routing Options</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28492#M5790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can anyone help me explain 3 type of VPN routing for example "&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center and to other satellites through center" &lt;/STRONG&gt;I have to add Center GW and two satellites gateways to the same vpn community?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL class="" style="color: #333333; margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center only&lt;/STRONG&gt;. No VPN routing actually occurs. Only connections between the satellite gateways and central gateway go through the VPN tunnel. Other connections are routed in the normal way&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center and to other satellites through center&lt;/STRONG&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite gateway to another satellite gateway is routed through the central gateway. Connection between satellite gateways and gateways that do not belong to the community are routed in the normal way.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;. Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2018 16:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28492#M5790</guid>
      <dc:creator>Worapong_Janloy</dc:creator>
      <dc:date>2018-09-20T16:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about VPN Routing Options</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28493#M5791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center only &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Means only communication between Center to any Satellite and viceversa will be allowed.&lt;/P&gt;&lt;P&gt;In case you had more than one Satellite, those devices would not be able to reach each other's LAN networks through tunnel. Only Center networks are reachable (as defined in encryption domain and policy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Allows to route inside VPN Community.&lt;/P&gt;&lt;P&gt;If you want to reach Satellite_B LAN from Satellite_A LAN; you will have to pass through Center (hub and spoke).&lt;/P&gt;&lt;P&gt;If you centrally manage all devices, by checking this option you would be able to route traffic from LAN_B to LAN_A and viceversa without any other configuration since the encryption domains are automatically negotiated with Center gateway to allow this.&lt;/P&gt;&lt;P&gt;If the Satellites are locally managed devices, you will have to manually add the domain of Satellite_B to Center's domain (from Satellite_A perspective) and the domain of Satellite_A to Center's domain (from Satellite_B perspective) additionally to the networks already configured for Center to allow routing between both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; font-size: 14px; padding: 0pt;"&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Allows you to route all traffic to Center gateway.&lt;/P&gt;&lt;P&gt;If you centrally manage all devices, by checking this option all traffic from Satellites (excluding local networks) would be sent to Central gateway. This is a way to set center Gateway as default route. By checking this option would allow not only Internet traffic, but to reach other VPN communities also (those where Center gateway participates).&lt;/P&gt;&lt;P&gt;If the Satellites are locally managed devices, you will have to configure an "universal tunnel" to allow Satellite to send all traffic to Center gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more information on VPN Admin Guide and more ways to route as you need by editing vpn_route.conf file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2018 22:52:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28493#M5791</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-09-20T22:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Confused about VPN Routing Options</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28494#M5792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good explain so many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 06:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Confused-about-VPN-Routing-Options/m-p/28494#M5792</guid>
      <dc:creator>Worapong_Janloy</dc:creator>
      <dc:date>2018-09-21T06:37:55Z</dc:date>
    </item>
  </channel>
</rss>

