<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to update RA encryption domain dynamically? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132611#M7772</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gateway is R80.40 and I have bunch of endpoint security VPN clients.&lt;/P&gt;
&lt;P&gt;hub mode is NOT enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example I want that checkpoint.com would be part of encryption domain. The problem is that I cannot add domain or any other clever object into encryption domain. Only host or network objects allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any ideas how it could be implemented easily? Maybe someone already got script working in action?&lt;/P&gt;
&lt;P&gt;I was thinking of resolving domain to IPs and then feeding them to API to create objects and pushing the policy. On next client connect new topology should be downloaded.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Oct 2021 10:30:51 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2021-10-26T10:30:51Z</dc:date>
    <item>
      <title>How to update RA encryption domain dynamically?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132611#M7772</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gateway is R80.40 and I have bunch of endpoint security VPN clients.&lt;/P&gt;
&lt;P&gt;hub mode is NOT enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example I want that checkpoint.com would be part of encryption domain. The problem is that I cannot add domain or any other clever object into encryption domain. Only host or network objects allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any ideas how it could be implemented easily? Maybe someone already got script working in action?&lt;/P&gt;
&lt;P&gt;I was thinking of resolving domain to IPs and then feeding them to API to create objects and pushing the policy. On next client connect new topology should be downloaded.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 10:30:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132611#M7772</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-10-26T10:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to update RA encryption domain dynamically?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132614#M7773</link>
      <description>&lt;P&gt;I think you have already answered your own question.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, why would you need to add a domain to the encryption domain of your VPN in the first place? Those network objects are supposed to be internal.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 11:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132614#M7773</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-10-26T11:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to update RA encryption domain dynamically?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132631#M7774</link>
      <description>&lt;P&gt;Between black (Hub mode) and white (internal network), grey color exist, where you might want to do it only for certain applications. For example where restriction is based on HQ IP. Because IP of the domain can change, ability to add domain object inside encryption domain would be extremely useful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it would be of interest for Checkpoint to implement it at some point.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 12:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132631#M7774</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-10-26T12:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to update RA encryption domain dynamically?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132656#M7775</link>
      <description>&lt;P&gt;The closest thing we have is:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000&amp;amp;partition=Basic&amp;amp;product=IPSec&lt;/A&gt;&lt;BR /&gt;There is also a customer release that allows for Updatable Objects and Dynamic Objects to be used for the encryption domain.&lt;BR /&gt;Please check with your local Check Point office for further details.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 18:03:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132656#M7775</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-26T18:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to update RA encryption domain dynamically?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132677#M7776</link>
      <description>&lt;P&gt;Yes, I am aware of this SK and it is indeed nice workaround playing with exclusion list.&lt;/P&gt;
&lt;P&gt;Thanks for heads-up, it was worth describing my problem here. I'll check with local office what they have.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 06:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-update-RA-encryption-domain-dynamically/m-p/132677#M7776</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-10-27T06:42:34Z</dc:date>
    </item>
  </channel>
</rss>

