<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB units SMS files for VPN fine-tuning in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/247515#M12538</link>
    <description>&lt;P&gt;No just an addition.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Apr 2025 14:15:05 GMT</pubDate>
    <dc:creator>Steffen_Appel</dc:creator>
    <dc:date>2025-04-28T14:15:05Z</dc:date>
    <item>
      <title>SMB units SMS files for VPN fine-tuning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/39541#M1613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SMB units SMS files for VPN fine-tuning are found in the &lt;EM&gt;CMP&lt;/EM&gt; directories &lt;EM&gt;lib&lt;/EM&gt; folder. There are several SKs for special configuration files on the SMS. For a SMS version managing a GW version, a special folder contains the - identically named - &lt;EM&gt;.def&lt;/EM&gt; files. Here is an overview of the corresponding SKs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sk108600 VPN Site-to-Site with 3rd party&lt;/EM&gt; shows fine-tuning VPN for special purposes using the user.def or the crypt.def file on SMS according to GW version. &lt;EM&gt;sk44852 How to configure a Site-to-Site VPN with a universal tunnel&lt;/EM&gt; and &lt;EM&gt;sk30919 Creating customized rules for Check Point Security Gateway - 'user.def' file&lt;/EM&gt; only make use of user.def. The user.def itself is somehow special as it resides in the &lt;EM&gt;$FWDIR/conf/&lt;/EM&gt; folder and is named corresponding to the GW version it will configure. An example for SMB devices managed by R80.10 SMS:&lt;/P&gt;&lt;PRE&gt;1100 with R75.20.x $FWDIR/conf/user.def.SFWR75CMP&lt;BR /&gt;1100 / 1200R / 1400 with R77.20.x $FWDIR/conf/user.def.SFWR77CMP&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;The locations of the user.def is listed in &lt;EM&gt;sk98239 Location of 'user.def' files on Security Management Server&lt;/EM&gt;, for location of the crypt.def file we have &lt;EM&gt;sk98241 Location of 'crypt.def' files on SMS&lt;/EM&gt;. Another example for SMB devices managed by R80.10 SMS:&lt;/P&gt;&lt;PRE&gt;1100 with R75.20.x /opt/CPSG80R75CMP-R80/lib/crypt.def&lt;BR /&gt;1100 / 1200R / 1400 with R77.20.x /opt/CPSFWR77CMP-R80/lib/crypt.def&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;Also very important is the vpn_route.conf from &lt;EM&gt;sk69726 VPN Routing does not work and traffic to other satellites leaves in "clear" when setting up SmartLSM profile in Star Community and choosing option "To center and to other satellites through center"&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you can find the other relevant documents by searching for the filenames: ftp.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk61781&lt;/EM&gt;&lt;/SPAN&gt;), vpn_table.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk923312&lt;/EM&gt;&lt;/SPAN&gt;), implied_rules.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk92281&lt;/EM&gt;&lt;/SPAN&gt;), base.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk95147&lt;/EM&gt;&lt;/SPAN&gt;), table.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk98339&lt;/EM&gt;&lt;/SPAN&gt;) and communities.def (&lt;SPAN style="font-size: 15px;"&gt;&lt;EM&gt;sk101052&lt;/EM&gt;&lt;/SPAN&gt;) in Support Center. To find all of them on the unit itself, in expert mode issue &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt; :&lt;/P&gt;&lt;PRE&gt;[Expert]# find /opt -name "xxxx.def"&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;It is very interesting that locally managed SMB units also have that files - &lt;EM&gt;crypt.def&lt;/EM&gt; can be found there in &lt;EM&gt;/pfrm2.0/config[1 / 2]/fw1/lib/ &lt;/EM&gt;and in &lt;EM&gt;/opt/fw1/lib/crypt.def. &lt;/EM&gt;See &lt;A _jive_internal="true" href="https://community.checkpoint.com/docs/DOC-2798-locally-managed-smbs-and-def-files"&gt;&lt;EM&gt;Locally managed SMBs and .def files&lt;/EM&gt;&lt;/A&gt; for details!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Mar 2018 15:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/39541#M1613</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-06T15:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: SMB units SMS files for VPN fine-tuning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/246237#M12453</link>
      <description>&lt;P&gt;On R82 for crypt.def you have all these_&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/opt/CPSFWR77CMP-R82/lib/crypt.def&lt;BR /&gt;/opt/CPSFWR80CMP-R82/lib/crypt.def&lt;BR /&gt;/opt/CPSFWR81CMP-R82/lib/crypt.def&lt;BR /&gt;/opt/CPSFWR82CMP-R82/lib/crypt.def&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 09:42:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/246237#M12453</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2025-04-11T09:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: SMB units SMS files for VPN fine-tuning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/246338#M12464</link>
      <description>&lt;P&gt;Is this a question?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 06:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/246338#M12464</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-04-14T06:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: SMB units SMS files for VPN fine-tuning</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/247515#M12538</link>
      <description>&lt;P&gt;No just an addition.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 14:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-units-SMS-files-for-VPN-fine-tuning/m-p/247515#M12538</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2025-04-28T14:15:05Z</dc:date>
    </item>
  </channel>
</rss>

