Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jose_Luis_Hdz
Participant

Overlap in Encryption Domains in Remote Access VPNs

Hello, everyone.

I hope you’re all doing well.

We’re currently working on an Azure tenant with two availability zones (primary and secondary).

In each Azure region, there’s a Check Point Security Gateway with the Mobile Access Blade and IPSec VPN enabled.

The customer has informed us that, regardless of which Security Gateway they are connected to, they should be able to access the same networks via the C2S VPN.

It should be noted that the two Security Gateways involved in this scenario are managed by the same Smart-1 Cloud.

In a typical scenario, where the encryption domains of the two Security Gateways are different, the routes are correctly injected into the VPN client. However, when we try to have both Security Gateways have exactly the same networks (full overlap), the routes are not injected into the VPN client.

Has anyone encountered a scenario similar to ours? What procedure or alternative would you recommend we use? Is this scenario supported by the technology?

We look forward to your kind assistance.

Best regards.

0 Kudos
1 Reply
spottex
Collaborator

We have the same the Encr Domains for two separate GW's and it is working, but it is not Azure. Maybe Azure registers the overlap. Try giving each gateway its own group to read from (not likely to improve but worth a try) "Gateway > Network Management > VPN Domain > Set specific VPN Domain for Gateways Communities", to possibly get each GW read the config and separate. Just a guess.

VPN client's local cache configuration may be corrupted or confused by the overlap??? From control panel uninstall Check Point mobile access agent and the CP SSL Network Extender service. Then reconnect to mobile access to reinstall. Or delete and recreate the profile is using one of the CP clients.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events