<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156364#M7319</link>
    <description>&lt;P&gt;CaseyB - See my reply to Chris above.&amp;nbsp; Mine is centrally managed...may be a difference between centrally and locally managed gateways...&lt;/P&gt;</description>
    <pubDate>Fri, 02 Sep 2022 18:35:57 GMT</pubDate>
    <dc:creator>Dr_Steve_Brule</dc:creator>
    <dc:date>2022-09-02T18:35:57Z</dc:date>
    <item>
      <title>Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156340#M7314</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a couple of SMB 1500 devices setup for various home users.&amp;nbsp; We set these devices up with the ability to sit on their private network at home so the appliance is setup as a DAIP gateway with a private DHCP address from their home network on the WAN interface of the SMB (did this to make it easy on the end use so they can just plug in the device at home and flexibility to move the device around).&lt;/P&gt;&lt;P&gt;Once they get plugged in, IPSEC VPN is configured and it will create a tunnel to the main site and have connectivity.&lt;/P&gt;&lt;P&gt;One limitation I found on the appliance itself - I'd like to send services such as DNS, NTP, ICMP from the appliance itself down the tunnel using the LAN IP of the appliance instead of the WAN IP.&amp;nbsp; Currently, those requests are trying to be sent down the tunnel using the WAN IP which could be any private IP on the home user's network.&amp;nbsp; I don't want to define the user's home networks as part of the encryption domain so if there is some kind of workaround to use the SMB's LAN IP to send those requests, that'd be great.&amp;nbsp; Any ideas on this?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 13:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156340#M7314</guid>
      <dc:creator>Dr_Steve_Brule</dc:creator>
      <dc:date>2022-09-02T13:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156359#M7316</link>
      <description>&lt;P&gt;In Advanced Settings search for "source" and you should find applicable options to assist i.e.&lt;/P&gt;
&lt;P&gt;"Use internal IP address for encrypted connections from local gateway"&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 16:10:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156359#M7316</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-02T16:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156360#M7317</link>
      <description>&lt;P&gt;Is there something similar for the 1430s? Searching for similar terms in Advanced Settings is telling me no.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 16:49:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156360#M7317</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2022-09-02T16:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156363#M7318</link>
      <description>&lt;P data-unlink="true"&gt;Forgot to mention - this is a centrally managed gateway.&amp;nbsp; Per&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/R80-20-15-Locally-Managed-Advanced-Settings/td-p/10621," target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/R80-20-15-Locally-Managed-Advanced-Settings/td-p/10621&lt;/A&gt;&amp;nbsp;it looks like "&lt;SPAN&gt;VPN Site to Site global settings - Use internal IP address for encrypted connections from local gateway" is a valid option for locally managed SMBs.&amp;nbsp; Hoping there may be something in GUIDBEdit for centrally managed...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 18:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156363#M7318</guid>
      <dc:creator>Dr_Steve_Brule</dc:creator>
      <dc:date>2022-09-02T18:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156364#M7319</link>
      <description>&lt;P&gt;CaseyB - See my reply to Chris above.&amp;nbsp; Mine is centrally managed...may be a difference between centrally and locally managed gateways...&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 18:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156364#M7319</guid>
      <dc:creator>Dr_Steve_Brule</dc:creator>
      <dc:date>2022-09-02T18:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcing SMB services from internal interface - ICMP, NTP, DNS to send over VPN</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156365#M7320</link>
      <description>&lt;P&gt;Found it -&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119415&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk119415&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Centrally&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;Managed Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Firmware R77.20.80 and higher (SMB-4577) adds the same functionality for Centrally Managed Devices.&lt;/P&gt;&lt;P&gt;In order to enable the feature a kernel parameter should be used - fw ctl set int fw_enc_conns_use_internal 1&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 18:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Sourcing-SMB-services-from-internal-interface-ICMP-NTP-DNS-to/m-p/156365#M7320</guid>
      <dc:creator>Dr_Steve_Brule</dc:creator>
      <dc:date>2022-09-02T18:55:41Z</dc:date>
    </item>
  </channel>
</rss>

