<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS traffic using S2S VPN is not working in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159951#M7601</link>
    <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;I have two checkpoint 750 and 730 devices connected to each other using VPN S2S.&lt;/P&gt;&lt;P&gt;IP traffic using VPN works without problem. I can access devices on the LAN from either side.&lt;/P&gt;&lt;P&gt;From the CP750 side, I have an Exchange Server 2019 ST server.&lt;/P&gt;&lt;P&gt;When Outlook is on the LAN, the CP730 cannot connect to Exchange Server 2019 because it does not send DNS queries via VPN.&lt;/P&gt;&lt;P&gt;How to configure the CP 750 and 730 for DNS queries to be sent over the S2S VPN tunnel.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 12:27:31 GMT</pubDate>
    <dc:creator>luk89as</dc:creator>
    <dc:date>2022-10-19T12:27:31Z</dc:date>
    <item>
      <title>DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159951#M7601</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;I have two checkpoint 750 and 730 devices connected to each other using VPN S2S.&lt;/P&gt;&lt;P&gt;IP traffic using VPN works without problem. I can access devices on the LAN from either side.&lt;/P&gt;&lt;P&gt;From the CP750 side, I have an Exchange Server 2019 ST server.&lt;/P&gt;&lt;P&gt;When Outlook is on the LAN, the CP730 cannot connect to Exchange Server 2019 because it does not send DNS queries via VPN.&lt;/P&gt;&lt;P&gt;How to configure the CP 750 and 730 for DNS queries to be sent over the S2S VPN tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 12:27:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159951#M7601</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-10-19T12:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159952#M7602</link>
      <description>&lt;P&gt;There is an advanced setting which if enabled will provide the behaviour as your describing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;"Do not encrypt local DNS requests"&lt;/P&gt;
&lt;P&gt;Worth checking before exploring elsewhere.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 12:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159952#M7602</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-19T12:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159955#M7603</link>
      <description>&lt;P&gt;In the advanced settings, I have set the following options:&lt;/P&gt;&lt;P&gt;Global VPN Site to Site settings - do not encrypt local DNS requests - TRUE&lt;/P&gt;&lt;P&gt;I set the setting as always about CP730 and CP 750.&lt;/P&gt;&lt;P&gt;Even so, I still don't have DNS traffic over the S2S VPN. You can see in the logs that it is encrypted.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:06:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159955#M7603</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-10-19T13:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159957#M7604</link>
      <description>&lt;P&gt;The other advanced option that may apply is:&lt;/P&gt;
&lt;P&gt;"Do not encrypt connections originating from the local gateway"&lt;/P&gt;
&lt;P&gt;Failing this if all other VPN parameters check out and you're on the latest build of R77.20.87 I would discuss it further with TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159957#M7604</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-19T13:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159965#M7606</link>
      <description>&lt;P&gt;In each of the configuration pages, for these two settings to be set to TRUE.&lt;/P&gt;&lt;P&gt;Screen in the appendix.&lt;/P&gt;&lt;P&gt;I don't know if it matters, but the S2S VPN connection is made using certificates.&lt;/P&gt;&lt;P&gt;Even though you select the option that it does not encrypt DNS traffic it does otherwise.&lt;/P&gt;&lt;P&gt;The log shows that traffic from the CP730 LAN is blocked on the CP 750 side.&lt;/P&gt;&lt;P&gt;Maybe a rule in the firewall needs to be created?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:37:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159965#M7606</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-10-19T13:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159967#M7607</link>
      <description>&lt;P&gt;Are both centrally managed? If so, check option in global properties "accept domain name over..."&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/159967#M7607</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-19T13:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/160023#M7610</link>
      <description>&lt;P&gt;&lt;BR /&gt;I started unencrypted DNS traffic over VPN.&lt;/P&gt;&lt;P&gt;In the S2S VPN settings I checked the option: "Allow traffic to the internet from remote site through this gateway."&lt;/P&gt;&lt;P&gt;I applied the setting to both Checkpoint devices.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/160023#M7610</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-10-20T06:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS traffic using S2S VPN is not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/160088#M7619</link>
      <description>&lt;P&gt;Do Not Encrypt Local DNS Requests of TRUE means that DNS requests won't be encrypted (sent over VPN).&lt;BR /&gt;What happens when you make it FALSE?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 19:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/DNS-traffic-using-S2S-VPN-is-not-working/m-p/160088#M7619</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-20T19:40:41Z</dc:date>
    </item>
  </channel>
</rss>

