<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connecting to BGP network through IPsec tunnel in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179006#M1523</link>
    <description>&lt;P&gt;What does the routing at the branches look like, are these gateways also performing NAT?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2023 03:38:52 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-04-25T03:38:52Z</dc:date>
    <item>
      <title>Connecting to BGP network through IPsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/178888#M1515</link>
      <description>&lt;P&gt;Hello, I have one group with two 6700 gateways and learned 172.18.1.0/24 network through BGP and has full access to this network.&lt;BR /&gt;&lt;BR /&gt;I have few CP 1530 gateways on remote places and all of them are connected to the Maestro GW through IPsec tunnels in same star community. I want them to be able to reach 172.18.1.0/24 network, so I have defined this network in the VPN encryption domain and created "accept" policy rule. When I try to connect to the network not even log shows up and fails.&lt;/P&gt;&lt;P&gt;In theory, this should be really simple. What could be the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 07:01:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/178888#M1515</guid>
      <dc:creator>Gombodorj2323</dc:creator>
      <dc:date>2023-04-24T07:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to BGP network through IPsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179000#M1522</link>
      <description>&lt;P&gt;Are all these 1530s managed with the same management?&lt;BR /&gt;Have you pushed policy to all relevant gateways?&lt;BR /&gt;What version/JHF is Maestro running and what firmware version/build # is used on the SMB appliances?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 02:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179000#M1522</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-25T02:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to BGP network through IPsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179006#M1523</link>
      <description>&lt;P&gt;What does the routing at the branches look like, are these gateways also performing NAT?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 03:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179006#M1523</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T03:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to BGP network through IPsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179007#M1524</link>
      <description>&lt;P&gt;1. It is in different management&lt;/P&gt;&lt;P&gt;2. Yes I'm testing on exactly 2 gateways.&lt;/P&gt;&lt;P&gt;3. Maestro is R81.10/Take79 and SMB is running R80.30. I haven't checked the specific firmware version I will when I can.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 04:47:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179007#M1524</guid>
      <dc:creator>Gombodorj2323</dc:creator>
      <dc:date>2023-04-25T04:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to BGP network through IPsec tunnel</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179008#M1525</link>
      <description>&lt;P&gt;Branch gateways have just a simple default rule to the ISP IP address that it is connecting to. Also branches have 172.10.X.X/25 local network on the internal interface and thats where I want to connect to&amp;nbsp;&lt;SPAN&gt;172.18.1.0/24 from.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried changing the VPN routing option in the community to all 3 of the option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VPN domain looks like this:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VPN domain of a branch GW = branch-local domain (172.10.X.X/25)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VPN domain of the Maestro = Maestro-local domain (172.18.1.0/24)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;172.10.X.X/25 -&amp;gt; tunnel -&amp;gt; Maestro -&amp;gt;&amp;nbsp;&lt;SPAN&gt;172.18.1.0/24&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 04:54:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Connecting-to-BGP-network-through-IPsec-tunnel/m-p/179008#M1525</guid>
      <dc:creator>Gombodorj2323</dc:creator>
      <dc:date>2023-04-25T04:54:08Z</dc:date>
    </item>
  </channel>
</rss>

