<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending wired and wireless internet different directions in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88254#M3697</link>
    <description>&lt;P&gt;I have a customer that wants to route wired traffic in their branch over a star VPN to headquarters as well as through to the internet.&amp;nbsp; There is a star vpn routing option to do just that. (To center, or through the center to other satellites, to internet&amp;nbsp;and other VPN targets)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their 1550 appliance at the branch office also has wireless in addition to wired.&amp;nbsp; They want that wireless to be like a guest wireless and just go straight out to the internet from that box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured that if that branch’s wireless network source is not included in the branch’s encryption domain that it might work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spoiler, I just tried it and it gave me an error, “encryption failure: Clear text packet should be encrypted.”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My feeling is that it might be a limitation of the VPN routing option and that all traffic either goes over the VPN tunnel or is just dropped, but that doesn’t sound right to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone tried this and was able to make it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2020 15:44:27 GMT</pubDate>
    <dc:creator>Jonathan_Lobl</dc:creator>
    <dc:date>2020-06-11T15:44:27Z</dc:date>
    <item>
      <title>Sending wired and wireless internet different directions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88254#M3697</link>
      <description>&lt;P&gt;I have a customer that wants to route wired traffic in their branch over a star VPN to headquarters as well as through to the internet.&amp;nbsp; There is a star vpn routing option to do just that. (To center, or through the center to other satellites, to internet&amp;nbsp;and other VPN targets)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their 1550 appliance at the branch office also has wireless in addition to wired.&amp;nbsp; They want that wireless to be like a guest wireless and just go straight out to the internet from that box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I figured that if that branch’s wireless network source is not included in the branch’s encryption domain that it might work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Spoiler, I just tried it and it gave me an error, “encryption failure: Clear text packet should be encrypted.”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My feeling is that it might be a limitation of the VPN routing option and that all traffic either goes over the VPN tunnel or is just dropped, but that doesn’t sound right to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone tried this and was able to make it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jonathan&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 15:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88254#M3697</guid>
      <dc:creator>Jonathan_Lobl</dc:creator>
      <dc:date>2020-06-11T15:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Sending wired and wireless internet different directions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88466#M3701</link>
      <description>&lt;P&gt;By default, the encryption domain (i.e. what goes over the VPN) includes all networks.&lt;BR /&gt;Sounds like you need to manually define it here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-06-14 at 12.23.51 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6745iD60E47F860E18C48/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-06-14 at 12.23.51 AM.png" alt="Screen Shot 2020-06-14 at 12.23.51 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 07:25:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88466#M3701</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-14T07:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sending wired and wireless internet different directions</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88819#M3728</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I convinced them to just route all internet from the branch with the same filtering policy as central and this issue went away.&lt;/P&gt;&lt;P&gt;Thanks anyways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 20:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sending-wired-and-wireless-internet-different-directions/m-p/88819#M3728</guid>
      <dc:creator>Jonathan_Lobl</dc:creator>
      <dc:date>2020-06-16T20:08:43Z</dc:date>
    </item>
  </channel>
</rss>

