<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site2Site VPN - Quantum Spark 2560. Peer ID and policy options in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/266412#M13512</link>
    <description>&lt;P&gt;Just to add to this discussion:&lt;BR /&gt;&lt;BR /&gt;The purpose of a VPN community is to manage multiple tunnels in a single object, useful when you have a central office and multiple branches connected to it with identical tunnel config.&lt;/P&gt;
&lt;P&gt;You can create VPN communities for locally managed Spark gateways that are connected to Spark Management in Infinity Portal. All Spark gateways are entitled to it. However, this is only for tunnels between your own Spark gateways managed by the same Spark Management. For externally managed peers you have to create the tunnel directly in the WebUI of the Spark itself.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jan 2026 23:27:48 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2026-01-02T23:27:48Z</dc:date>
    <item>
      <title>Site2Site VPN - Quantum Spark 2560. Peer ID and policy options</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265212#M13505</link>
      <description>&lt;P&gt;I am configuring a site2site VPN from our 2560 to a remote Checkpoint firewall. On our side of the config, for IKEv2 it wants us to input the Peer ID. Is that the IP of the remote side VPN?&lt;/P&gt;&lt;P&gt;Also, I am used to using Smartconsole (these are locally managed), and when creating rules for a VPN, we add the 'Community' to the rule. In the Spark I do not see where I specify the community. Is that just taken care of by virtue of the fact that I identified the local/remote networks used in the Encryption Domains?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 19:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265212#M13505</guid>
      <dc:creator>JaySon_2021</dc:creator>
      <dc:date>2025-12-12T19:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN - Quantum Spark 2560. Peer ID and policy options</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265226#M13506</link>
      <description>&lt;P&gt;I believe the Peer ID is the IP, yes.&lt;BR /&gt;The concept of a VPN community is not relevant for locally managed SMB devices.&lt;BR /&gt;The local/remote encryption domains should be configured correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2025 23:10:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265226#M13506</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-12T23:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN - Quantum Spark 2560. Peer ID and policy options</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265230#M13507</link>
      <description>&lt;P&gt;I also think that would be the case with peer ID. I could be mistaken, but I recall setting the IP as peer ID few times before, recently with harmony sase.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Dec 2025 03:18:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265230#M13507</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-13T03:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN - Quantum Spark 2560. Peer ID and policy options</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265271#M13508</link>
      <description>&lt;P&gt;Some additional factors.&lt;/P&gt;
&lt;P&gt;I believe the default is to use [Key ID] for locally managed Spark.&lt;BR /&gt;This can be confirmed/configured from the WEB UI -&amp;gt; [Device] -&amp;gt; [Advanced Settings] -&amp;gt; [VPN Site to Site global settings - IKEv2 key type].&lt;BR /&gt;&lt;BR /&gt;The available options are:&lt;/P&gt;
&lt;P&gt;(1) Key ID (Default)&lt;BR /&gt;(2) IP address&lt;BR /&gt;(3) FQDN&lt;BR /&gt;&lt;BR /&gt;Make sure the key type matches what is configured with the peer vpn site configuration.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ikev2_keyid.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32431i6F74B9DC60605BF6/image-size/large?v=v2&amp;amp;px=999" role="button" title="ikev2_keyid.png" alt="ikev2_keyid.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Dec 2025 02:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/265271#M13508</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2025-12-15T02:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site VPN - Quantum Spark 2560. Peer ID and policy options</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/266412#M13512</link>
      <description>&lt;P&gt;Just to add to this discussion:&lt;BR /&gt;&lt;BR /&gt;The purpose of a VPN community is to manage multiple tunnels in a single object, useful when you have a central office and multiple branches connected to it with identical tunnel config.&lt;/P&gt;
&lt;P&gt;You can create VPN communities for locally managed Spark gateways that are connected to Spark Management in Infinity Portal. All Spark gateways are entitled to it. However, this is only for tunnels between your own Spark gateways managed by the same Spark Management. For externally managed peers you have to create the tunnel directly in the WebUI of the Spark itself.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 23:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site2Site-VPN-Quantum-Spark-2560-Peer-ID-and-policy-options/m-p/266412#M13512</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2026-01-02T23:27:48Z</dc:date>
    </item>
  </channel>
</rss>

