- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Is it possible to use an exclusion group as part of a VPN encryption domain? Or do I have to list out all the network objects that I want and not include the ones I don't want?
Thanks!
I did for one customer whose internal subnet had another devices reachable without VPN (Switches and Routers). On my case, excluding only the hosts (ex. Remote Domain Net 192.168.1.0/24, excluding 192.168.1.2 and 192.168.1.3) It worked without issues.
And you used an exclusion group? Object Explorer -> Network Objects -> Groups -> Group with Exclusions ?
Yes. I configured the exclusion group as encryption domain.
Even worked excluding the external IP of remote gateway, so this way, was not included on encryption domain automatically.
How did you exactly do it ?
You defined the public ip of the gateway as a host object, then included the host object inside a network group object and then excluded it in the excluded section of a network group with exclusions object ?
Evan,
as @KennyManrique mentioned, it is no problem to use a group with exclusions as encryption domain.
I think 80% of our customers are doing this.
Wolfgang
Yes, depending on the size of the excluded hosts/networks it may cause a change in behavior for the size of the subnets proposed in IKE Phase 2, particularly when hosts (/32) are excluded. When exclusions are used, the VPN domain is recalculated into multiple networks/subnets to exclude the desired addresses. You can use tools like Danny Jung's VPN Domain One-liner to see this in action:
Groups with exclusions have many limitations one should be aware of. (sk97246, sk101506, sk107543, sk107417, ..)
I've also mentioned this in my article about Properly defining the Internet within a security policy.
Hello Dany,
the most important thing when working with Encryption Domains and Exclusions is this SK sk39679
you have to switch to "one tunnel per gateway pair" as this SK sk39679 states
best regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 22 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 2 | |
| 2 |
Thu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASEThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 09 Jul 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #9 - What's New with Check Point Email SecurityFri 10 Jul 2026 @ 11:00 AM (IDT)
CheckMates Live Netherlands - Sessie 48: Nieuwe Check Point Workspace SecurityTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY