<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange issue with routing/nat on site-2-site in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126853#M5521</link>
    <description>&lt;P&gt;i didnt even know it possible to "exclude" that.. how would you go around doing that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 19:28:06 GMT</pubDate>
    <dc:creator>skandshus</dc:creator>
    <dc:date>2021-08-12T19:28:06Z</dc:date>
    <item>
      <title>Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126609#M5511</link>
      <description>&lt;P&gt;Hi everyone..&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am hosting a service for a customer on a public accessible IP address… &amp;nbsp;i have then set up a site-2-site vpn for backup purposes because&amp;nbsp;&lt;SPAN&gt;the customer also has a local server that needs backup.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the setup is.&lt;/P&gt;&lt;P&gt;local customer subnet192.168.80.0/24 &amp;amp; 192.168.50.0/24 (with client that needs to access navision service at my public ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the customer is accessing an RDP service using dns name navision.it-connect.nu&lt;/P&gt;&lt;P&gt;it resolves to my external ip&amp;nbsp;194.182.21.148&lt;/P&gt;&lt;P&gt;on the customer site I have a 1570 appliance&lt;/P&gt;&lt;P&gt;and In my hosting center I’m running checkpoint open server.&lt;/P&gt;&lt;P&gt;the local subnet for the navision server is 10.10.114.2&lt;/P&gt;&lt;P&gt;I have both firewall and nat rule in place allowing remote access.. everything is fine..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I need to establish a site to site vpn from MY local subnet at the hosting center at 10.10.150.0/24 because I need to take a backup of a server at the customer local site.. that server is located at 192.168.80.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can establish the site to site tunnel fine and everything is working. But when I do that, then it is no longer possible for the customer at their local subnet 192.168.0.0/24 &amp;amp; 192.168.50.0/24 to access the navision server any longer, even though both the navision subnet AND the customers local subnet has not been defined in the encryption domain(which is on purpose)..&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;can anybody shed some light on what is happening ? I have another customer where this is not an issue… I even tried to do a copy/paste of the vpn community setup to rule out error, but it still blocks the remote access..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I’m short.. vpn tunnel connects successfully allowing my backup server to reach customer subnet and do the backup but it breaks the customers access to the navision server when they try to reach it using the dns name/wan up address..&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 19:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126609#M5511</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2021-08-11T19:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126751#M5516</link>
      <description>&lt;P&gt;Is your external ip&amp;nbsp;194.182.21.148 included in the encryption domain ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:22:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126751#M5516</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-08-12T14:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126752#M5517</link>
      <description>&lt;P&gt;No the external Ip is not included… on purpose though.. wouldn’t that cause issues?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126752#M5517</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2021-08-12T14:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126756#M5518</link>
      <description>&lt;P&gt;As the clients try to connect to that IP, it would cause issues, so i have asked&amp;nbsp;8)&lt;/img&gt; Are the clients NATed behind the GW IP ?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126756#M5518</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-08-12T14:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126821#M5519</link>
      <description>&lt;P&gt;Both subnet on each side is behind hide nat on the gateway…&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from my perspective I would expect the subnets to only be routed, if a host would try to access navision.it-connect:8787&lt;/P&gt;&lt;P&gt;i would expect them to hit the wan interface and NOT for some reason go through the tunnel.. even though the IP address /gateway is also used as the peer gateway.. and I have no idea how to “explain” it regarding a TAC and making sure they understood 100% what the problem is..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 14:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126821#M5519</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2021-08-12T14:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126829#M5520</link>
      <description>&lt;P&gt;Try to exclude only&amp;nbsp;&lt;SPAN&gt;Microsoft Remote Desktop on TCP port 3389 from your&amp;nbsp;VPN Community.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 15:09:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126829#M5520</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-08-12T15:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with routing/nat on site-2-site</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126853#M5521</link>
      <description>&lt;P&gt;i didnt even know it possible to "exclude" that.. how would you go around doing that?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 19:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Strange-issue-with-routing-nat-on-site-2-site/m-p/126853#M5521</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2021-08-12T19:28:06Z</dc:date>
    </item>
  </channel>
</rss>

