<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN issue on 770 Appliance in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93630#M3976</link>
    <description>&lt;P&gt;You can exclude the peers routable IP from Enc Domain, that is, let all connections from internal networks to the public IP go thru Internet, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86582&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk86582: Excluding subnets in &lt;STRONG&gt;encryption&lt;/STRONG&gt; &lt;STRONG&gt;domain&lt;/STRONG&gt; &lt;STRONG&gt;from&lt;/STRONG&gt; accessing a specific VPN community&lt;/A&gt;,&amp;nbsp;then this traffic will go thru internet. Strange, but possible...&lt;/P&gt;
&lt;P&gt;Please refer to&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2798-locally-managed-smbs-and-def-files" target="_blank"&gt;&lt;EM&gt;Locally managed SMBs and .def files&lt;/EM&gt;&lt;/A&gt;&amp;nbsp;for implementation !&lt;/P&gt;</description>
    <pubDate>Fri, 07 Aug 2020 10:20:25 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-08-07T10:20:25Z</dc:date>
    <item>
      <title>Site to Site VPN issue on 770 Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93615#M3970</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have configured a Site to Site VPN on our 770 appliance with one of our partners, and everything works fine.&lt;/P&gt;&lt;P&gt;However their is an issue accessing a web site which resolves to the same public IP as the VPN tunnel. For some reason the CP is sending the traffic to the VPN tunnel and not out the internet.&lt;/P&gt;&lt;P&gt;Has anyone faced this before? or any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 00:07:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93615#M3970</guid>
      <dc:creator>KevinA</dc:creator>
      <dc:date>2020-08-07T00:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN issue on 770 Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93626#M3974</link>
      <description>&lt;P&gt;A public routable IP can exist only once, so there is something very fishy going on here and i must not comment...&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 07:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93626#M3974</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-07T07:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN issue on 770 Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93629#M3975</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Sorry if my question / description of the issue was not clear.&lt;/P&gt;&lt;P&gt;The web site that cannot be accessed is also hosted by the same partner that we have the Site-to-Site terminating on.&lt;/P&gt;&lt;P&gt;(So the Tunnel IP is the same for the URL - they have got some kind of portforward set up on&amp;nbsp; their end)&lt;/P&gt;&lt;P&gt;Unfortunately they cannot/will not let us access the URL via the private IP.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 08:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93629#M3975</guid>
      <dc:creator>KevinA</dc:creator>
      <dc:date>2020-08-07T08:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN issue on 770 Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93630#M3976</link>
      <description>&lt;P&gt;You can exclude the peers routable IP from Enc Domain, that is, let all connections from internal networks to the public IP go thru Internet, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86582&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk86582: Excluding subnets in &lt;STRONG&gt;encryption&lt;/STRONG&gt; &lt;STRONG&gt;domain&lt;/STRONG&gt; &lt;STRONG&gt;from&lt;/STRONG&gt; accessing a specific VPN community&lt;/A&gt;,&amp;nbsp;then this traffic will go thru internet. Strange, but possible...&lt;/P&gt;
&lt;P&gt;Please refer to&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2798-locally-managed-smbs-and-def-files" target="_blank"&gt;&lt;EM&gt;Locally managed SMBs and .def files&lt;/EM&gt;&lt;/A&gt;&amp;nbsp;for implementation !&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 10:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93630#M3976</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-08-07T10:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN issue on 770 Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93798#M3991</link>
      <description>I owe u a beer mate &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Tue, 11 Aug 2020 01:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-issue-on-770-Appliance/m-p/93798#M3991</guid>
      <dc:creator>KevinA</dc:creator>
      <dc:date>2020-08-11T01:45:52Z</dc:date>
    </item>
  </channel>
</rss>

