<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257393#M1637</link>
    <description>&lt;P&gt;I tried Manual Exclusion But it gave me no difference, Will Try the method you linked&lt;/P&gt;</description>
    <pubDate>Tue, 16 Sep 2025 15:58:55 GMT</pubDate>
    <dc:creator>NJTsunss</dc:creator>
    <dc:date>2025-09-16T15:58:55Z</dc:date>
    <item>
      <title>Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257273#M1635</link>
      <description>&lt;P&gt;I have A Problem When I enable Manual Encryption Domain, My RA VPN clients not only Receive Routes That i have Created in Manually Encryption Domain, but they also receive routes for Active Interfaces which are behind Checkpoint.&lt;BR /&gt;&lt;BR /&gt;I need my VPN Clients to only Reicieve Routes For The Networks I have Defined inside Encryption Domain, Is this Perhaps Some kind of A Bug Or am i Missing Configuration?&lt;/P&gt;&lt;P&gt;I use Endpoint Security VPN&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257273#M1635</guid>
      <dc:creator>NJTsunss</dc:creator>
      <dc:date>2025-09-15T10:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257392#M1636</link>
      <description>&lt;P&gt;Expected behavior.&lt;BR /&gt;Have you explicitly tried excluding them here (under Exclude Networks):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 523px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31483iB67241DA9BEC87A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, you're probably going to have to do something like:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/VPN-traffic-exclusion-with-crypt-def/td-p/167592" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/VPN-traffic-exclusion-with-crypt-def/td-p/167592&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On a locally managed Quantum Spark appliance, after editing crypt.def, you will need to execute an fw_configload from Expert mode OR reboot the appliance for the change to take effect.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 15:56:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257392#M1636</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-16T15:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257393#M1637</link>
      <description>&lt;P&gt;I tried Manual Exclusion But it gave me no difference, Will Try the method you linked&lt;/P&gt;</description>
      <pubDate>Tue, 16 Sep 2025 15:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257393#M1637</guid>
      <dc:creator>NJTsunss</dc:creator>
      <dc:date>2025-09-16T15:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257524#M1638</link>
      <description>&lt;P&gt;I tried The Method You linked but still no luck, Currently I'm checking routes via Route print, the routes I get are this:&lt;BR /&gt;&lt;BR /&gt;0.0.0.0 255.255.255.255 172.17.10.2 172.17.10.1 1&lt;BR /&gt;10.100.120.0 255.255.255.0 172.17.10.2 172.17.10.1 1&lt;BR /&gt;10.70.0.1 255.255.255.255 172.17.10.2 172.17.10.1 1&lt;BR /&gt;10.128.128.2 255.255.255.255 172.17.10.2 172.17.10.1 1&lt;BR /&gt;127.0.0.1 255.255.255.255 172.17.10.2 172.17.10.1 1&lt;BR /&gt;192.168.5.0 255.255.255.0 172.17.10.2 172.17.10.1 1&lt;BR /&gt;&lt;BR /&gt;the only routes I should be getting are, 192.168.5.0 and 10.10.10.0&lt;BR /&gt;other addresses like 10.70.0.1 and 10.128.128.2 are my interface Ip addresses that are connected to other devices.&lt;BR /&gt;&lt;BR /&gt;I tried Crypt.def&lt;BR /&gt;Changed it like this for example to exclude 10.70.0.1:&lt;BR /&gt;&lt;BR /&gt;From this&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;#ifndef NON_VPN_TRAFFIC_RULES&lt;BR /&gt;#ifdef USE_NON_VPN_DESTINATIONS&lt;BR /&gt;#define NON_VPN_TRAFFIC_RULES (dst in non_vpn_destinations)&lt;BR /&gt;#else&lt;BR /&gt;#define NON_VPN_TRAFFIC_RULES 0&lt;BR /&gt;#endif&lt;BR /&gt;#endif&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;#endif /* __crypt_def__ */&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;To this&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;#ifndef NON_VPN_TRAFFIC_RULES&lt;BR /&gt;#ifdef USE_NON_VPN_DESTINATIONS&lt;BR /&gt;#define NON_VPN_TRAFFIC_RULES (dst=10.70.0.1)&lt;BR /&gt;#else&lt;BR /&gt;#define NON_VPN_TRAFFIC_RULES 0&lt;BR /&gt;#endif&lt;BR /&gt;#endif&lt;/P&gt;&lt;P&gt;#endif /* __crypt_def__ */&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;But 10.70.0.1 still stayed in Laptop routing table, am I doing something wrong?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 17:31:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257524#M1638</guid>
      <dc:creator>NJTsunss</dc:creator>
      <dc:date>2025-09-17T17:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark 1600 Locally Managed Ra VPN Encryption Domain Problem</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257528#M1639</link>
      <description>&lt;P&gt;This may not be possible on locally managed Quantum Spark appliances, or this isn't the right procedure for that.&lt;BR /&gt;Suggest a TAC case here.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 17:37:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Quantum-Spark-1600-Locally-Managed-Ra-VPN-Encryption-Domain/m-p/257528#M1639</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-17T17:37:18Z</dc:date>
    </item>
  </channel>
</rss>

