<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Routing Action in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97007#M9901</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about action in vpn log.&lt;BR /&gt;What is the meaning of VPN Routing in logs?&lt;BR /&gt;Does it mean users accessing an internal network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2020 11:19:44 GMT</pubDate>
    <dc:creator>Thin</dc:creator>
    <dc:date>2020-09-18T11:19:44Z</dc:date>
    <item>
      <title>VPN Routing Action</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97007#M9901</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question about action in vpn log.&lt;BR /&gt;What is the meaning of VPN Routing in logs?&lt;BR /&gt;Does it mean users accessing an internal network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 11:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97007#M9901</guid>
      <dc:creator>Thin</dc:creator>
      <dc:date>2020-09-18T11:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing Action</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97015#M9902</link>
      <description>&lt;P&gt;A VPN Routing action indicates that traffic was decrypted from one VPN tunnel, then re-encrypted straight into another VPN tunnel.&amp;nbsp; Usually happens between satellites in the same Star-based VPN Community if allowed in the Community settings, but can also happen between different VPN Communities as authorized by the vpn_route.conf file.&amp;nbsp; Note that the per-VPN Community VPN domain feature in R80.40 can help fine tune this behavior, see here:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164417&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;sk164417: Traffic from one VPN community not routed to another VPN community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 12:26:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97015#M9902</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-09-18T12:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing Action</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97017#M9903</link>
      <description>&lt;P&gt;Remote user come in and access an address over a S2S vpn&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 12:31:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/97017#M9903</guid>
      <dc:creator>Andreas_Aust</dc:creator>
      <dc:date>2020-09-18T12:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing Action</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/251670#M9904</link>
      <description>&lt;P class=""&gt;Hello,&lt;/P&gt;&lt;P class=""&gt;I am attempting to establish a VPN tunnel between two satellite devices (SPOKEs—non-Check Point products) and a central Check Point Security Gateway (HUB).&lt;/P&gt;&lt;P class=""&gt;Sample Encryption Domain for:&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SPOKE A: 172.20.18.69&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SPOKE B: 10.40.90.5&lt;/P&gt;&lt;H3&gt;Current Configuration:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;Created separate VPN communities for each SPOKE, with the HUB as the central gateway in both.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Used identical encryption parameters for both VPN communities.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;The goal is to allow traffic from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SPOKE A&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to pass through the HUB to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SPOKE B&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Created a static route on the HUB for routing traffic to SPOKE B encryption domain [10.40.90.5] from SPOKE A encryption domain [172.20.18.69].&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Access Control Rule:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;A single rule was created with each gateway’s encryption domain as both the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;source&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;destination&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;VPN Community&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field in the rule references both VPN community objects (one for each SPOKE).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;(See attached image for the rule configuration.)&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Issue Observed:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;Traffic from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SPOKE B&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;reaches the HUB, and logs confirm it is being&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;VPN-routed&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;However, the traffic&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;does not reach SPOKE B’s encryption domain&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;Both Phase 1 and Phase 2 tunnels between the HUB and each SPOKE are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;up&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;EM&gt;(See attached VPN-routed traffic log for details.)&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Request for Assistance:&lt;/H3&gt;&lt;P class=""&gt;Could you help identify what might be wrong with this VPN routing configuration? Alternatively, do you have any recommended resources for troubleshooting similar VPN routing scenarios?&lt;/P&gt;&lt;P class=""&gt;Should I set the VPN Routing option for both VPN communities:- "to Center and to other satellites through center" or "To Center only"&lt;/P&gt;&lt;P class=""&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jun 2025 12:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Action/m-p/251670#M9904</guid>
      <dc:creator>SintayehuCSE</dc:creator>
      <dc:date>2025-06-20T12:46:11Z</dc:date>
    </item>
  </channel>
</rss>

