<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN encryption domain problem (Star community) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47853#M12495</link>
    <description>I probably understand what you mean, In other words, when defining the scope of the encryption domain, the encryption domain of the data center end and the branch end cannot be an inclusion relationship, and must be an independent network segment.</description>
    <pubDate>Wed, 20 Mar 2019 01:28:54 GMT</pubDate>
    <dc:creator>yumin_hu</dc:creator>
    <dc:date>2019-03-20T01:28:54Z</dc:date>
    <item>
      <title>IPSec VPN encryption domain problem (Star community)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47715#M12493</link>
      <description>&lt;P&gt;I would like to ask experts a question about the scope of the VPN encryption domain definition.&lt;BR /&gt;If a branch of a company needs to access the company data center through IPSec VPN, the encryption domains at both ends are defined as: branch = 10.1.5.0/24, company data center = 10.0.0.0/8&lt;BR /&gt;If the encryption domain is defined as such, will there be any problem with IPSec VPN communication?&lt;img id="smileyembarrassed" class="emoticon emoticon-smileyembarrassed" src="https://community.checkpoint.com/i/smilies/16x16_smiley-embarrassed.png" alt="Smiley Embarassed" title="Smiley Embarassed" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 13:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47715#M12493</guid>
      <dc:creator>yumin_hu</dc:creator>
      <dc:date>2019-03-19T13:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN encryption domain problem (Star community)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47731#M12494</link>
      <description>Encryption domains cannot overlap in this manner. Not to mention, you'll have routing issues. The branch side will need to be NATTED to talk to the datacenter side and the datacenter side will need to refer to the branch side by the NATted IPs.</description>
      <pubDate>Tue, 19 Mar 2019 13:52:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47731#M12494</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-19T13:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN encryption domain problem (Star community)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47853#M12495</link>
      <description>I probably understand what you mean, In other words, when defining the scope of the encryption domain, the encryption domain of the data center end and the branch end cannot be an inclusion relationship, and must be an independent network segment.</description>
      <pubDate>Wed, 20 Mar 2019 01:28:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-VPN-encryption-domain-problem-Star-community/m-p/47853#M12495</guid>
      <dc:creator>yumin_hu</dc:creator>
      <dc:date>2019-03-20T01:28:54Z</dc:date>
    </item>
  </channel>
</rss>

