<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hub and Spoke Policy Based VPN Spark Firewall in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hub-and-Spoke-Policy-Based-VPN-Spark-Firewall/m-p/282334#M14142</link>
    <description>&lt;P&gt;Hello, is there someone could help me with my issue on my VPN. I have two branch offices connected to the Head Office via Site to Site VPN. Branch 1 device (172.16.86.59) needs to telnet to Branch 2 (10.201.20.45). From branch 2 perspective, the source should be coming from HO local network using (172.16.20.133). I also created a SNAT in the Head Office Firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Branch 1 to HO: Local Network 172.16.86.0/24 | Remote Network: 172.16.20.0/24&lt;BR /&gt;&lt;BR /&gt;HO to Branch 1 : Local Network 172.16.20.0/24 | Remote Network: 172.16.86.0/24&lt;BR /&gt;HO to Branch 2: Local Network 172.16.20.0/24 | Remote Network : 10.201.20.0/24 &amp;amp; 10.201.22.0/24&lt;BR /&gt;&lt;BR /&gt;Branch 2 to HO: Local Network: 10.201.20.0/24 and 10.201.22.0/24 | Remote Network: 172.16.20.0/24&lt;BR /&gt;&lt;BR /&gt;In my testing, I successfully telnet to 10.201.20.45 from Branch 1 172.16.86.59 after uncheking the "disable NAT" in VPN Settings for both site. But when telnet is successful. The web portal in the 10.201.22.0/24 is not accessible in the HO.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also the tunnel status has a warning sign, indicating that only Phase 1 is up.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2026 04:21:30 GMT</pubDate>
    <dc:creator>CEEJAY</dc:creator>
    <dc:date>2026-09-15T04:21:30Z</dc:date>
    <item>
      <title>Hub and Spoke Policy Based VPN Spark Firewall</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hub-and-Spoke-Policy-Based-VPN-Spark-Firewall/m-p/282334#M14142</link>
      <description>&lt;P&gt;Hello, is there someone could help me with my issue on my VPN. I have two branch offices connected to the Head Office via Site to Site VPN. Branch 1 device (172.16.86.59) needs to telnet to Branch 2 (10.201.20.45). From branch 2 perspective, the source should be coming from HO local network using (172.16.20.133). I also created a SNAT in the Head Office Firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Branch 1 to HO: Local Network 172.16.86.0/24 | Remote Network: 172.16.20.0/24&lt;BR /&gt;&lt;BR /&gt;HO to Branch 1 : Local Network 172.16.20.0/24 | Remote Network: 172.16.86.0/24&lt;BR /&gt;HO to Branch 2: Local Network 172.16.20.0/24 | Remote Network : 10.201.20.0/24 &amp;amp; 10.201.22.0/24&lt;BR /&gt;&lt;BR /&gt;Branch 2 to HO: Local Network: 10.201.20.0/24 and 10.201.22.0/24 | Remote Network: 172.16.20.0/24&lt;BR /&gt;&lt;BR /&gt;In my testing, I successfully telnet to 10.201.20.45 from Branch 1 172.16.86.59 after uncheking the "disable NAT" in VPN Settings for both site. But when telnet is successful. The web portal in the 10.201.22.0/24 is not accessible in the HO.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Also the tunnel status has a warning sign, indicating that only Phase 1 is up.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2026 04:21:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hub-and-Spoke-Policy-Based-VPN-Spark-Firewall/m-p/282334#M14142</guid>
      <dc:creator>CEEJAY</dc:creator>
      <dc:date>2026-09-15T04:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Hub and Spoke Policy Based VPN Spark Firewall</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hub-and-Spoke-Policy-Based-VPN-Spark-Firewall/m-p/282419#M14147</link>
      <description>&lt;P&gt;It's clear the branch offices are some form of Spark appliance, what about the hub site?&lt;BR /&gt;Are these units centrally managed or?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 14:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hub-and-Spoke-Policy-Based-VPN-Spark-Firewall/m-p/282419#M14147</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-16T14:48:32Z</dc:date>
    </item>
  </channel>
</rss>

