<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Route Based VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34463#M7246</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to establish route based VPN and I have created numbered VTIs on both firewalls with help of SK113735. But traffic is going in clear text, it is not encrypting traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if any other setting, creating community etc. needs to be done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Feb 2019 17:22:20 GMT</pubDate>
    <dc:creator>Gaurav_Pandya</dc:creator>
    <dc:date>2019-02-19T17:22:20Z</dc:date>
    <item>
      <title>Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34463#M7246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to establish route based VPN and I have created numbered VTIs on both firewalls with help of SK113735. But traffic is going in clear text, it is not encrypting traffic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if any other setting, creating community etc. needs to be done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 17:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34463#M7246</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-19T17:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34464#M7247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gaurav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please review the second portion of this&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100726" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100726"&gt;How to configure IPsec VPN tunnel between Check Point Security Gateway and Amazon Web Services VPC using static routes&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to see the creation of the VPN community for route-based VPNs. It should be more broadly applicable than just AWS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 18:07:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34464#M7247</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-02-19T18:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34465#M7248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Vladimir for the response.&lt;/P&gt;&lt;P&gt;I will try it to configure.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 10:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34465#M7248</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-20T10:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34466#M7249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gaurav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A while back I have created a template to be filled for a set of AWS tunnels with or without cluster, with or without BGP and this looks like this, below is the actual code created by the program:&lt;/P&gt;&lt;P&gt;Non cluster version&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79305" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79305_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;Cluster version:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79306" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79306_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This template was built with Filemaker Pro all you fill is the fields on the left top all the rest is filled based on that info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 13:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34466#M7249</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-20T13:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34467#M7250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Maarten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 15:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34467#M7250</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-21T15:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34468#M7251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured route based VPN but tunnel is not coming UP. fails at phase1. Just want to confirm that I have configured VTIs in correct manner.&lt;/P&gt;&lt;P&gt;Environment : Single GW (Not in cluster)&lt;/P&gt;&lt;P&gt;VTI : Local address - Public IP of My GW (External IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Remote address - Public IP of Remote GW (External IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static Route : Next hope is Public IP of Remote GW.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 15:56:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34468#M7251</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-21T15:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34469#M7252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I said in my post have a look at the first image, in the top left you enter the 169.254 addresses you get for local and remote, the look at the first lines of the CLISH code which configures the VTI's it shows you the 169.254 addresses, not the real IP's of the hosts.&lt;/P&gt;&lt;P&gt;For the routing you also use the 169.254 address as the next hop.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 18:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34469#M7252</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-21T18:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34470#M7253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Maarten,&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;I have given IP address to VTI other than interface IP. We can also give private IP address as well. Now Tunnel is UP and working as expected.&lt;/P&gt;&lt;P&gt;I have also enabled OSPF and it is running fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2019 12:21:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34470#M7253</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-25T12:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34471#M7254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am summarizing the steps of route based VPN configuration so it will be helpful for others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Create empty encryption domains and assign to each gateway.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Create VTI interface in Gaia webUI.&amp;nbsp; for remote peer use object name rather than IP.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Add routes for remote side encryption domain toward VTI interface. - Here you can use static or any other dynamic routing protocol like OSPF.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;Enabled OSPF on VTI interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79682_Capture2.PNG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt;You can follow sk113735 for point 1-3 configuration. Please note that you can use any fake IP address as Local &amp;amp; Remote addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL start="4"&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Fetch topology on gateway object in SmartDashboard.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Add VIPs if cluster.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Use the external interfaces in link selection.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Add rules with directional VPN: source real encryption domains (not null domain), dest same, VPN column: internal_clear to VPN Community, VPN Community to VPN Community, and VPN Community to internal_clear in each VPN rule.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/79683_Capture3.PNG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL start="8"&gt;&lt;LI style="margin: 0in 0in .0001pt 27.0pt;"&gt;&lt;SPAN style="color: black;"&gt; Fw monitor shows little o go to VTI, and big O go to external interface, with external IP's.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 17:08:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/34471#M7254</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-02-28T17:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/51105#M10094</link>
      <description>&lt;P&gt;Thank you man for sharing... Life saver!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 22:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/51105#M10094</guid>
      <dc:creator>Dami</dc:creator>
      <dc:date>2019-04-16T22:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/67819#M13860</link>
      <description>Hi Gaurav_Pandya, but if we want to add WAN redundancy links, should we do other configurations ?</description>
      <pubDate>Tue, 19 Nov 2019 15:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/67819#M13860</guid>
      <dc:creator>armandxhafa</dc:creator>
      <dc:date>2019-11-19T15:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/73486#M14881</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are these steps also applicable if doing route based vpn with Cisco?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 20:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/73486#M14881</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-01-27T20:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/87343#M17552</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have Policy based VPN already running on Checkpoint FW.&lt;/P&gt;&lt;P&gt;Can I create route based VPN also in same FW ?&lt;/P&gt;&lt;P&gt;Can we create route based VPN in virtual FW (VS) ?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 16:53:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/87343#M17552</guid>
      <dc:creator>sunilspj</dc:creator>
      <dc:date>2020-06-04T16:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/87344#M17553</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Can I create route based VPN also in same FW ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Yes but policy/domain-based VPN will take precedence for identifying interesting traffic.&amp;nbsp; See my response here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Access-Control-Products/Site-to-Site-VPN-policy-based-and-routing-behavior/m-p/85902/highlight/true#M1916" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Access-Control-Products/Site-to-Site-VPN-policy-based-and-routing-behavior/m-p/85902/highlight/true#M1916&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;Can we create route based VPN in virtual FW (VS) ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;No, VSX does not support the VPN Tunnel Interfaces (VTIs) that are required for route-based VPN, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700&amp;amp;partition=Basic&amp;amp;product=VSX," target="_blank" rel="noopener"&gt;sk79700:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;VSX&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;supported features on R75.40VS and above.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 12:23:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/87344#M17553</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-05T12:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/112601#M21180</link>
      <description>&lt;P&gt;Hi Maarten,&lt;/P&gt;&lt;P&gt;thank you for sharing this good stuff. But I still don't get what the the AWS cluster IP addresses are meaning (100.100.*) and how those addresses are being used in the vpn tunnels 1 and 2 using different networks (local and remote) which is 100.100.* and 169.254.* addresses on numbered tunnel interface. I would expect a /30 network or at least the same network addresses on tunnel interfaces on prem and on AWS side. This still confuses me. Can you please explain this a bit more? Really appreciated.&lt;/P&gt;&lt;P&gt;Many thanks in advance!&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 06:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Route-Based-VPN/m-p/112601#M21180</guid>
      <dc:creator>watermanns</dc:creator>
      <dc:date>2021-03-06T06:55:22Z</dc:date>
    </item>
  </channel>
</rss>

