<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic multiple VPN IPsec : select one tunnel in function of the source subnet in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14223#M13338</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a simple question on a Checkpoint VPN functionality. If you have more than one tunnel, is it possible to select one tunnel in function of the source subnet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the context of my request :&lt;/P&gt;&lt;P&gt;On my network, I have an IPsec tunnel between a Security Gateway Virtual Edition and a cluster of two Checkpoint 2200 T-110. Each member of the cluster build his own tunnel with the Security Gateway VE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to set up a new &lt;SPAN&gt;Security Gateway Virtual Edition and&amp;nbsp;&lt;/SPAN&gt;buid new tunnels with this VM. The need is to split trafics from different network&amp;nbsp;and have them arrive on two separate platforms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My whish is that hosts belonging to the subnet 192.168.30.0/24 use IPsec_tunnel_A and hosts from subnets 192.168.40.0/24, 10.20.0.0/16 use the new IPsec_tunnel_B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't succeed in setting up this idea. Do you know if this is possible ? All my devises works on Gaia OS 77.30.&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jul 2018 14:31:34 GMT</pubDate>
    <dc:creator>OSMOZ_Enedis</dc:creator>
    <dc:date>2018-07-30T14:31:34Z</dc:date>
    <item>
      <title>multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14223#M13338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a simple question on a Checkpoint VPN functionality. If you have more than one tunnel, is it possible to select one tunnel in function of the source subnet ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the context of my request :&lt;/P&gt;&lt;P&gt;On my network, I have an IPsec tunnel between a Security Gateway Virtual Edition and a cluster of two Checkpoint 2200 T-110. Each member of the cluster build his own tunnel with the Security Gateway VE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to set up a new &lt;SPAN&gt;Security Gateway Virtual Edition and&amp;nbsp;&lt;/SPAN&gt;buid new tunnels with this VM. The need is to split trafics from different network&amp;nbsp;and have them arrive on two separate platforms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My whish is that hosts belonging to the subnet 192.168.30.0/24 use IPsec_tunnel_A and hosts from subnets 192.168.40.0/24, 10.20.0.0/16 use the new IPsec_tunnel_B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didn't succeed in setting up this idea. Do you know if this is possible ? All my devises works on Gaia OS 77.30.&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2018 14:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14223#M13338</guid>
      <dc:creator>OSMOZ_Enedis</dc:creator>
      <dc:date>2018-07-30T14:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14224#M13339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I’m understanding what you’re asking, you’re trying to create two VPN tunnels to same encryption domain.&lt;/P&gt;&lt;P&gt;In which case, I would review the Multiple Entry Point configuration options here:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm?topic=documents/R77/CP_R77_VPN_AdminGuide/13812" title="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/html_frameset.htm?topic=documents/R77/CP_R77_VPN_AdminGuide/13812"&gt;VPN R77 Versions Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this isn’t what you are asking, please clarify by providing more details about what you’re trying to achieve and why.&lt;/P&gt;&lt;P&gt;A diagram showing the gateways, subnets, and desired traffic flows would also be very helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 01:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14224#M13339</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-31T01:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14225#M13340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Main question here is where do the subnets live? Is&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;subnet 192.168.30.0/24 (Indirectly) connected to the first VE and&amp;nbsp;&lt;SPAN&gt;subnets 192.168.40.0/24, 10.20.0.0/16 (indirectly) connected to the second VE?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;If so then there is no issue at all and you can just make sure the routing is set accordingly on the VE side and on the VPN domains you set the correct networks for the 2 VE's, (which network can I reach via which VE).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;Hope this helps getting you in the right direction.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 05:26:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14225#M13340</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-31T05:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14226#M13341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your first answers. I&amp;nbsp;attach a complete diagram of my situation (sorry for the blue stencils...).&amp;nbsp;&lt;/P&gt;&lt;P&gt;For now I only have IPsec tunnels in green. I need to split trafic from users of SiteA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like that User1 only use green tunnels&amp;nbsp; whereas User2 and User3 should only use pink tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The demande comes from security department : they ask that admin&amp;nbsp;users (from subnet 192.168.30.0/24) use a different VPN gateway from non-admin users (from subnets 192.168.40.0/24 and 10.20.0.0/24).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So do you think that it is possible for the cluster XXX to choose green or pink tunnel in function of the source subnet which is sending a request/reply (and in function of the destination of course) ?&lt;BR /&gt;For example User1 and User2 need to reach the server 172.16.0.9, can we force User1 to take green tunnel and User2 to take pink tunnel ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="explicative diagram" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/67734_diagram post checkpoint mates.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 10:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14226#M13341</guid>
      <dc:creator>OSMOZ_Enedis</dc:creator>
      <dc:date>2018-07-31T10:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14227#M13342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have partially overlapping encryption domains, which is not supported.&lt;/P&gt;&lt;P&gt;Specifically:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;VPN_siteB_Pink and VPN_siteB_Green share 172.16.0.0/13&lt;/LI&gt;&lt;LI&gt;VPN_siteC_Pink and VPN_siteC_Green share 172.24.0.0/13&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The encryption domains either have to &lt;STRONG&gt;fully&lt;/STRONG&gt; overlap or not overlap at all.&lt;/P&gt;&lt;P&gt;If they don't overlap at all, you can set it up so the relevant group can use only the relevant VPN--problem solved.&lt;/P&gt;&lt;P&gt;If they fully overlap, then there isn't a way to force&amp;nbsp;specific subnets to use a specific&amp;nbsp;VPN tunnel (through MEP or any other method).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A better approach in this case would be&amp;nbsp;to have admins use a Remote Access VPN client to access the desired gateway (e.g. through Mobile Access Blade or similar).&lt;/P&gt;&lt;P&gt;Then you can leave the encryption domains as "partially overlapping."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 15:54:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14227#M13342</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-31T15:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14228#M13343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you again for your useful explanations and for your substitution proposal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that it is not possible to partially overlap encryption domains. And it is not possible de choose specific VPN tunnel neither.&lt;/P&gt;&lt;P&gt;I have notice that I could use Remote Access VPN client to access the desired gateway. In my situation, it is not an easy job considering the large amount of users involved for the heavy client installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I think to another possibility : is that possible to define two Virtual System on the Checkpoint 2200 to workaround ? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would have four virtual firewalls on my site A (siteA_2200_a_vsxAdmin + siteA_2200_a_vsxNonAdmin&amp;nbsp; + siteA_2200_b_vsxAdmin&amp;nbsp; + siteA_2200_b_vsxNonAdmin) used to buid four IPsec tunnels to site B and four IPsec tunnels to site C. In this case I would have no limitation of encryption domains overlapping because all tunnels &lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;in destination to&lt;/SPAN&gt;&lt;/SPAN&gt; site B or all tunnels &lt;SPAN class="" lang="en"&gt;&lt;SPAN class=""&gt;in destination to&lt;/SPAN&gt;&lt;/SPAN&gt; site C will be on different equipments. Is that correct ? If yes, do you know the license to activate VSX on 2200 models ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 14:00:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14228#M13343</guid>
      <dc:creator>OSMOZ_Enedis</dc:creator>
      <dc:date>2018-08-01T14:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14229#M13344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class=""&gt;&lt;DIV style="left: 66.2px; top: 897.942px; font-size: 15px; font-family: sans-serif; transform: scaleX(1.0775);"&gt;I found the licences informations (they are noticed in the correponding model datasheet).&lt;/DIV&gt;&lt;DIV style="left: 66.2px; top: 897.942px; font-size: 15px; font-family: sans-serif; transform: scaleX(1.0775);"&gt;Check Point 2200 appliance : virtual system package&lt;/DIV&gt;&lt;DIV style="left: 66.2px; top: 897.942px; font-size: 15px; font-family: sans-serif; transform: scaleX(1.0775);"&gt;&amp;nbsp; 3 Virtual Systems package : &lt;STRONG&gt;CPSB-VS-3&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV style="left: 66.2px; top: 897.942px; font-size: 15px; font-family: sans-serif; transform: scaleX(1.0775);"&gt;&amp;nbsp; 3 Virtual Systems package for HA/VSLS : &lt;STRONG&gt;CPSB-VS-3-VSLS&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 14:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14229#M13344</guid>
      <dc:creator>OSMOZ_Enedis</dc:creator>
      <dc:date>2018-08-01T14:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14230#M13345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or you could use VSX &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I would make sure you add additional RAM to your 2200 as that will obviously require a bit more RAM.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2018 16:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14230#M13345</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-01T16:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: multiple VPN IPsec : select one tunnel in function of the source subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14231#M13346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="" lang="en"&gt;&lt;SPAN&gt;OK great.&lt;/SPAN&gt; &lt;SPAN class=""&gt;I have all the information to choose a solution that meets my needs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you Dameon and Maarten for your help.&lt;SPAN class=""&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2018 09:56:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/multiple-VPN-IPsec-select-one-tunnel-in-function-of-the-source/m-p/14231#M13346</guid>
      <dc:creator>OSMOZ_Enedis</dc:creator>
      <dc:date>2018-08-02T09:56:46Z</dc:date>
    </item>
  </channel>
</rss>

