<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing on VPN in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128010#M5574</link>
    <description>&lt;P&gt;Hi Gaetano,&lt;/P&gt;&lt;P&gt;I assume you're using Domain based VPN. Could you share with us both encryption domain objects?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 20:04:53 GMT</pubDate>
    <dc:creator>KennyManrique</dc:creator>
    <dc:date>2021-08-25T20:04:53Z</dc:date>
    <item>
      <title>Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/127997#M5573</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Good Morning, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need to connect via site-to-site VPN from site A where the CP 730 appliance firewall is installed to site B where a Sophos firewall is installed that I do not manage. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The site-to-site VPN works correctly and is active. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Requests from clients of site A that may belong to different VLANs (see the table) must be routed to site B.&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;SITE A (CHECK POINT 730) TO SITE B (SOPHOS)&lt;/TD&gt;&lt;TD width="50%"&gt;Destination IP Subnet&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;Source IP Subnet&lt;/TD&gt;&lt;TD width="50%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;192.168.1.0/24 (Site A)&lt;/TD&gt;&lt;TD width="50%"&gt;172.20.43.0/24 (Site B)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;192.168.10.0/24 (Site A)&lt;/TD&gt;&lt;TD width="50%"&gt;172.20.43.0/24 (Site B)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;192.168.201.0/24 (Site A)&lt;/TD&gt;&lt;TD width="50%"&gt;172.20.43.0/24 (Site B)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately I can't route them correctly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I used Tracert and it seems that they are routed through the Internet instead of through VPN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you help me to solve the problem? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks and Best Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Gaetano&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 15:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/127997#M5573</guid>
      <dc:creator>Gaetano_Nicosia</dc:creator>
      <dc:date>2021-08-25T15:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128010#M5574</link>
      <description>&lt;P&gt;Hi Gaetano,&lt;/P&gt;&lt;P&gt;I assume you're using Domain based VPN. Could you share with us both encryption domain objects?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 20:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128010#M5574</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2021-08-25T20:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128013#M5575</link>
      <description>&lt;P&gt;It’s a 730, which is managed locally.&lt;BR /&gt;And the message should have been posted in the SMB space,&lt;BR /&gt;But yes, let’s see precisely how you’ve configured the VPN, specifically the remote Encryption Domain.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 20:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128013#M5575</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-25T20:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128053#M5578</link>
      <description>&lt;P&gt;Thank You for reply.&lt;/P&gt;&lt;P&gt;I opened the Firewall GUI and edited the VPN.&amp;nbsp;&lt;SPAN&gt;Please see the picture for the vpn configuration&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="remotesite.png" style="width: 739px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13531iEB4406EE93BB73AD/image-size/large?v=v2&amp;amp;px=999" role="button" title="remotesite.png" alt="remotesite.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the Advanced tab I don't find the encryption domain, but only in the TAB Remote site.&lt;/P&gt;&lt;P&gt;In Remote Site Encryption domain I have these methods:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Define Remote network topology manually&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Route all traffic through this site&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Encrypt according to routing table&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Hydden behind external IP of the remote gateway&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Is the point 1) the correct configuration?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also this is the configuration in the Advanced TAB&lt;/SPAN&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="advanced.png" style="width: 733px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13532i5832F12F2A5CAD43/image-size/large?v=v2&amp;amp;px=999" role="button" title="advanced.png" alt="advanced.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And this is the configuration in the TAB Encryption&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Encryption.png" style="width: 734px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13533iD919F1BC2DC6A31A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Encryption.png" alt="Encryption.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I look forward to your welcome reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Gaetano&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 05:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128053#M5578</guid>
      <dc:creator>Gaetano_Nicosia</dc:creator>
      <dc:date>2021-08-26T05:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128152#M5580</link>
      <description>&lt;P&gt;It was in the first screenshot at the bottom.&lt;BR /&gt;Now let's double check the local encryption domain.&lt;BR /&gt;Hopefully it looks something like:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 905px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13547i661DB508F2F33974/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;There should also be a rule in Access Policy &amp;gt; Firewall &amp;gt; Policy &amp;gt;&amp;nbsp;&lt;SPAN class="cp-title-text"&gt;Incoming, Internal and VPN traffic permitting the relevant traffic, possibly with the option "Match only for encrypted traffic" enabled.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 16:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128152#M5580</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-26T16:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128272#M5587</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank You for reply.&lt;/P&gt;&lt;P&gt;I have solved setting "Define local network topology manually" and adding the requested subnet.&lt;/P&gt;&lt;P&gt;After I have create the proper rules in "&lt;SPAN&gt;Access Policy &amp;gt; Firewall &amp;gt; Policy &amp;gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="cp-title-text"&gt;Incoming, Internal and VPN traffic".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cp-title-text"&gt;Please&amp;nbsp;can you explain me what is the purpose of the option "Match only for encrypted traffic"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cp-title-text"&gt;Thank You and Best regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cp-title-text"&gt;Gaetano&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 05:58:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128272#M5587</guid>
      <dc:creator>Gaetano_Nicosia</dc:creator>
      <dc:date>2021-08-28T05:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128275#M5588</link>
      <description>&lt;P&gt;That option means the rule would apply only if the traffic went over a VPN connection.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 08:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128275#M5588</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-28T08:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Routing on VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128280#M5589</link>
      <description>&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 14:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Routing-on-VPN/m-p/128280#M5589</guid>
      <dc:creator>Gaetano_Nicosia</dc:creator>
      <dc:date>2021-08-28T14:26:53Z</dc:date>
    </item>
  </channel>
</rss>

