<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Creating a policy for encrypting RAVPN traffic on a S2S VPN towards HO. in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193888#M4520</link>
    <description>&lt;P&gt;Is the HO network part of the RA encdom?&lt;/P&gt;&lt;P&gt;Is hub mode enabled at the moment?&lt;/P&gt;&lt;P&gt;VPN Clients &amp;gt; Remote Access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for why the first rule doesn't match, i think its down to it having the specific S2S vpn in the VPN collumn when your traffic is coming from the RA vpn.&lt;BR /&gt;&lt;BR /&gt;Try leaving the VPN column as "any" and the gateway might just do the trick.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;also, have you a log of a remote access user accessing HO at the moment?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Sep 2023 13:12:46 GMT</pubDate>
    <dc:creator>Machine_Head</dc:creator>
    <dc:date>2023-09-29T13:12:46Z</dc:date>
    <item>
      <title>Creating a policy for encrypting RAVPN traffic on a S2S VPN towards HO.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193886#M4518</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement to allow the RAVPN network traffic towards HO network using a S2S tunnel &amp;amp; the RAVPN network should be translated to a Host IP 10.x.x.x (SNAT).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S2S VPN is UP &amp;amp; created a Hide NAT policy for translating the source in encrypted traffic &amp;amp; also created a security policy for allowing the encrypted traffic &amp;amp; assigned the respective VPN community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, The traffic is getting hit by the RAVPN policy only but not by the policy that i have created for the S2S tunnel.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 12:20:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193886#M4518</guid>
      <dc:creator>shantilalSuthar</dc:creator>
      <dc:date>2023-09-29T12:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a policy for encrypting RAVPN traffic on a S2S VPN towards HO.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193887#M4519</link>
      <description>&lt;P&gt;attached are the policies.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 12:28:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193887#M4519</guid>
      <dc:creator>shantilalSuthar</dc:creator>
      <dc:date>2023-09-29T12:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a policy for encrypting RAVPN traffic on a S2S VPN towards HO.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193888#M4520</link>
      <description>&lt;P&gt;Is the HO network part of the RA encdom?&lt;/P&gt;&lt;P&gt;Is hub mode enabled at the moment?&lt;/P&gt;&lt;P&gt;VPN Clients &amp;gt; Remote Access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for why the first rule doesn't match, i think its down to it having the specific S2S vpn in the VPN collumn when your traffic is coming from the RA vpn.&lt;BR /&gt;&lt;BR /&gt;Try leaving the VPN column as "any" and the gateway might just do the trick.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;also, have you a log of a remote access user accessing HO at the moment?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193888#M4520</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-09-29T13:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Creating a policy for encrypting RAVPN traffic on a S2S VPN towards HO.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193893#M4521</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Is the HO network part of the RA encdom?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, For routing the HO network via RAVPN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hub mode is disabled.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;also, have you a log of a remote access user accessing HO at the moment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, Logging is enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Will try with 'any' in VPN column &amp;amp; check.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Creating-a-policy-for-encrypting-RAVPN-traffic-on-a-S2S-VPN/m-p/193893#M4521</guid>
      <dc:creator>shantilalSuthar</dc:creator>
      <dc:date>2023-09-29T13:54:58Z</dc:date>
    </item>
  </channel>
</rss>

