Hello everybody
I'm writing this post in the hope that someone has experienced the same issue. I'm trying to publish a service on the internet; the service is behind a site-to-site VPN that connects two Check Point clusters. The issue is that the request reaches the device, performs the destination NAT correctly, but the traffic is not being sent through the VPN.
In the following schema could understand better the connection that i need to realize. The external ip is static.
Based on this, i create the following in the Internet Firewall.
1. A Rule that allows communication between External IP and Public IP.
2. A NAT rule that converts the Public IP into Internal IP address.
3. In the VPN community (Both firewalls are check point managed by the same smart-1), i add the External IP address in the local domain of internet firewall.
4. And finally I have installed policy in the both firewalls, but the traffic doesnt go trough the VPN, that is currently working with other internal connections.
I have tried to perform a FW monitor and I only see the i packet, but in the smart monitor appears the initial connection from External IP to Public IP and the NATed Destination (Internal IP)
I think the issue is the internet firewall doesnt identify this traffic as VPN traffic
I dont know if i am making any mistake... any ideas?
Thank you in advance!