<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude single IP from Peer VPN IP range in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176460#M5232</link>
    <description>&lt;P&gt;I also just discovered that exclusion group objects exist. Do you know if using an exclusion group would cause any issues if I use that as the Satellite VPN domain?&lt;/P&gt;&lt;P&gt;It would be a simpler approach and be easier to share with my other techs.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Mar 2023 15:34:35 GMT</pubDate>
    <dc:creator>NorthernNetGuy</dc:creator>
    <dc:date>2023-03-28T15:34:35Z</dc:date>
    <item>
      <title>Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176450#M5229</link>
      <description>&lt;P&gt;I have a VPN community for a B2B connection set up, with their VPN Domain containing a /21, that all works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is 1 IP address in that /21 that is for a public website that we don't want to to route over the VPN, and I'm trying to figure out how to exclude it from being routed over that VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried setting up a NAT rule to translate the source to an different IP than the one used for that community, but it still attempts to route over the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also tried setting up a static route, setting the next hop to the IP used as our default gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I exclude an address from being routed thru that domain?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:27:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176450#M5229</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-28T14:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176456#M5230</link>
      <description>&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/VPN-traffic-exclusion-with-crypt-def/m-p/167592#M27836" target="_self"&gt;crypt.def is your friend&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176456#M5230</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-03-28T14:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176458#M5231</link>
      <description>&lt;P&gt;Thanks Danny! The SK for crypt.def was a little daunting and not clear how to specifically exclude an address, but that posts solution explains it very well!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:18:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176458#M5231</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-28T15:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176460#M5232</link>
      <description>&lt;P&gt;I also just discovered that exclusion group objects exist. Do you know if using an exclusion group would cause any issues if I use that as the Satellite VPN domain?&lt;/P&gt;&lt;P&gt;It would be a simpler approach and be easier to share with my other techs.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 15:34:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176460#M5232</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-28T15:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176463#M5233</link>
      <description>&lt;P&gt;As &lt;A href="https://community.checkpoint.com/t5/Management/Properly-defining-the-Internet-within-a-security-policy/td-p/10561" target="_self"&gt;this article&lt;/A&gt; describes, groups with exclusions may have issues when used with VPN encryption domains. It might work, just test it and keep a close eye on the &lt;A href="https://community.checkpoint.com/t5/Scripts/One-liner-to-show-VPN-topology-on-gateways/td-p/57975" target="_self"&gt;calculated result&lt;/A&gt;. I understand you are looking for an easy solution. However, your task it not easy by design. You could also create a group containing multiple network objects describing your /21 network without that single IP address in order to use that manually crafted network group as your new encryption domain. However, keep in mind Check Point performs &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Site-to-site-Disconnects-amp-Questions/m-p/175570/highlight/true#M32055" target="_self"&gt;supernetting&lt;/A&gt; by default, so you might still end up with a /21 encryption domain. That's why crypt.def is your friend.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 06:07:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176463#M5233</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2023-03-29T06:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176470#M5234</link>
      <description>&lt;P&gt;I really appreciate the in depth response! I'll experiment with the exclusion group, but it looks like I'll likely need to go with defining an exclusion within crypt.def.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'll try and update this post with my results once I've tested, for anyone that might stumble upon this post in the future.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 17:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176470#M5234</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2023-03-28T17:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176472#M5235</link>
      <description>&lt;P&gt;TAC told me that exclusion group as encryption domain are not supported even if you can use them from Smart Console&lt;BR /&gt;&lt;BR /&gt;&amp;gt;- Exchanged the network group with exclusions(not supported in the encryption domain) with a standard network group&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 18:10:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176472#M5235</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2023-03-28T18:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176473#M5236</link>
      <description>&lt;P&gt;I use this&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; You could also create a group containing multiple network objects describing your /21 network without that single IP address in &amp;gt;order to use that manually crafted network group as your new encryption domain.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;+ force the firewall to use a specific subnet editing user.def.FW1&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 18:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176473#M5236</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2023-03-28T18:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176500#M5238</link>
      <description>&lt;P&gt;Exclusion groups ARE supported for Remote Access VPN:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167000&lt;/A&gt;&lt;BR /&gt;However, that’s relatively recent and for the specific use case it was designed for (Remote Access).&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 22:51:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176500#M5238</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-28T22:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude single IP from Peer VPN IP range</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176560#M5239</link>
      <description>&lt;P&gt;ok , i used them in s2s vpn&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 11:53:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-single-IP-from-Peer-VPN-IP-range/m-p/176560#M5239</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2023-03-29T11:53:46Z</dc:date>
    </item>
  </channel>
</rss>

