<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN and SmartLSM doesn't works in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175242#M8517</link>
    <description>&lt;P&gt;Run command -&amp;gt; ip r g 20.20.20.100 and see path its taking. Confirm first it is correct and if so, we can run fw monitor to verify.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 18:32:24 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-03-17T18:32:24Z</dc:date>
    <item>
      <title>VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175241#M8516</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm trying in my LAB to create a VPN from a CheckPoint Gateway and several 1570R managed by SmartProvisiong.&lt;/P&gt;&lt;P&gt;Every SMB is connected to a SmartProvisiong of a CMA in my MDS and use a cellular interface to reach my network.&lt;/P&gt;&lt;P&gt;The CheckPoint Gateway is managed by the same CMA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed SmartProvisioning Adming Guide, but I see only some tunnel_test packet and no other traffic.&lt;/P&gt;&lt;P&gt;I don't have any route to EncryptionDomain in CheckPoint Gateway even if I try to use permanent tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The EncryptionDomain of the Gateway is configured with a group containing a subnet.&lt;/P&gt;&lt;P&gt;The EncryptionDomain on SmartLSM Gateway is configured Manual (on Topology page) witha range of IP that are used as NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic coming to Gateway from it's EncryptionDomain is dropped as:&lt;/P&gt;&lt;P&gt;# fw ctl zdebug + drop | grep 20.20.20.100&lt;BR /&gt;@;389050;[vs_0];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=1 20.20.20.100:1 -&amp;gt; 10.10.10.9:0 dropped by fw_log_ip_routing_failure Reason: IP routing failed (ipout routing failure);&lt;/P&gt;&lt;P&gt;Can some one help me?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;M&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 18:13:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175241#M8516</guid>
      <dc:creator>Marco32</dc:creator>
      <dc:date>2023-03-17T18:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175242#M8517</link>
      <description>&lt;P&gt;Run command -&amp;gt; ip r g 20.20.20.100 and see path its taking. Confirm first it is correct and if so, we can run fw monitor to verify.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 18:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175242#M8517</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-17T18:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175243#M8518</link>
      <description>&lt;P&gt;#ip r g 20.20.20.10&lt;BR /&gt;20.20.20.100 via 10.176.2.200 dev eth1 src 10.176.2.90cache&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#ip r g 10.10.10.9&lt;/P&gt;&lt;P&gt;RTNETLINK answers: Network is unreachable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;20.20.20.100 is on Gateway side , 10.10.10.9 is on SMB&lt;/P&gt;&lt;P&gt;Traffic need to start from 20.20.20.100 to 10.10.10.9&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 18:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175243#M8518</guid>
      <dc:creator>Marco32</dc:creator>
      <dc:date>2023-03-17T18:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175245#M8519</link>
      <description>&lt;P&gt;Can you draw simple diagram showing how this is configured and whats supposed to access what on the other side? Even basic paint diagram would help : - )&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 18:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175245#M8519</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-17T18:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175247#M8520</link>
      <description>&lt;P&gt;We need to find out WHY that IP shows unreachable, thats the key here.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 18:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175247#M8520</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-17T18:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN and SmartLSM doesn't works</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175375#M8537</link>
      <description>&lt;P&gt;Hi the_rock,&lt;/P&gt;&lt;P&gt;main issue seems that no route are present on Gateway and on SMB. I see tunnel_test from SMB to Gateway but VPN is marked as down.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 10:18:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-and-SmartLSM-doesn-t-works/m-p/175375#M8537</guid>
      <dc:creator>Marco32</dc:creator>
      <dc:date>2023-03-20T10:18:59Z</dc:date>
    </item>
  </channel>
</rss>

