- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a question about Site-Site VPN, and my concern is that the client computers from LAN_A could not access the server from LAN_B (RDP protocol).
VPN Community
Type: Star
Name: Asia
Center Gateways: fw-HongKong
Satellite Gateways: fw-Indonesia (LAN_A) and fw-Malaysia (LAN_B)
VPN Routing- To center and to other satellites through center
fw-HongKong
Gateway: Checkpoint 2200
Version: R77.30 Build 204
fw-Indonesia
Gateway: Checkpoint 1450
Version: R77.20
fw-Malaysia
Gateway: Checkpoint 1100
Version: R77.20
Keep in mind that above gateways are also a satellite gateways of another VPN Community (Star) which is Global. Upon checking the SmartLog, I noticed that the traffic is trying to encrypt in HQ gateway which is part of the Global Community, and is being dropped. I want to know how the traffic can be routed to the Center gateway in Asia (which is fw-HongKong) and reach the server in LAN_B which is behind fw-Malaysia gateway.
I already added the required rule in the destination Policy but it still failing, I guess the traffic is routed to the Center gateways in Global Community? Any ideas what to check?
Thanks for the time in reading from a newbie ![]()
How specific are the encryption domains configured for each gateway, do they overlap at all?
Is NAT enabled or disabled in each community, note more advanced configuration of the VPN routing is possible if required using vpn_route.conf.
note more advanced configuration of the VPN routing is possible if required using vpn_route.conf.
can the traffic be routed to another satellite gateway by configuring vpn_route.conf? can you please give a hint to force it? i mean is it possible that the traffic from fw-Indonesia can reach the server in fw-Malaysia by passing the Center gateway fw-HongKong?
I got this, and thank. I was able to update the $FWDIR/conf/vpn_route.conf in the Security Management Server
I just noticed from the SmartLog, the traffic is trying to Encrypt to Global Community instead of Asia VPN Community. I want the traffic to be Encrypt/Decrypt in my Center Gateway which is fw-HongKong
Any idea guys?
As above I would also check that your VPN Domains are configured specific enough to avoid overlaps. You may have to leverage the "manual" option to achieve.

Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY