<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Mesh Tunnel Question on On-Premise Smart-1 server/Quantum Spark 1600 Firewalls in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/265146#M13504</link>
    <description>&lt;P&gt;understood!&amp;nbsp; thank you for the prompt reply! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Dec 2025 19:47:31 GMT</pubDate>
    <dc:creator>rdiaz</dc:creator>
    <dc:date>2025-12-11T19:47:31Z</dc:date>
    <item>
      <title>VPN Mesh Tunnel Question on On-Premise Smart-1 server/Quantum Spark 1600 Firewalls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/264768#M13490</link>
      <description>&lt;P&gt;Greetings CheckMates,&lt;/P&gt;&lt;P&gt;I'm still fairly new to Check Point and trying to understand how the VPN Tunnels work the Quantum Spark world of firewalls.&lt;/P&gt;&lt;P&gt;I had an incident today where my internet connection went down (this is where my Smart-1 Server lives/on-premise with 2-HA Pair of 1600s firewall).&amp;nbsp; I noticed that none of my mesh connections worked during the outage (between other sites since I have about 7 of them).&amp;nbsp; Is the Smart-1 keeping those connections alive and if for any reason the Smart-1 server goes down the mesh goes down with it?&lt;/P&gt;&lt;P&gt;and if this is so, how can I create a mesh network that doesn't rely on the Smart-1 server or do I need to go Cloud with Check Point to avoid this from happening?&lt;/P&gt;&lt;P&gt;Any input is very appreciated. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Dec 2025 22:39:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/264768#M13490</guid>
      <dc:creator>rdiaz</dc:creator>
      <dc:date>2025-12-08T22:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Mesh Tunnel Question on On-Premise Smart-1 server/Quantum Spark 1600 Firewalls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/265145#M13503</link>
      <description>&lt;P&gt;One management dependency for VPNs is the Internal Certificate Authority.&lt;BR /&gt;If the management is down for an extended period of time, this will cause VPNs to fail since they cannot access the CRL...which is located on the management.&lt;BR /&gt;This is described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk100731" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100731&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You have a couple options here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use a third-party CA and certificates (which don't have a dependency on the management, but must be managed manually)&lt;/LI&gt;
&lt;LI&gt;Disable CRL checking, which is not recommended:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk21156" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk21156&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 11 Dec 2025 19:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/265145#M13503</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-11T19:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Mesh Tunnel Question on On-Premise Smart-1 server/Quantum Spark 1600 Firewalls</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/265146#M13504</link>
      <description>&lt;P&gt;understood!&amp;nbsp; thank you for the prompt reply! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Dec 2025 19:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-Mesh-Tunnel-Question-on-On-Premise-Smart-1-server-Quantum/m-p/265146#M13504</guid>
      <dc:creator>rdiaz</dc:creator>
      <dc:date>2025-12-11T19:47:31Z</dc:date>
    </item>
  </channel>
</rss>

