- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Consider a local management- and log server (SMS) and a gateway (cluster) on location A.
What is best practice to setup a remote gateway (cluster) on location B, under control of the SMS on location A.
Locations A and B are connected over the Internet.
My first thought is to setup a site-to-site IPSec VPN between the two sites and have the management traffic passing the VPN.
However, if the VPN fails (e.g., due to an incorrect policy installation), we also loose the management connection to location B. And there is no (easy) way to install the proper policy to get the VPN working again.
Should we keep the traffic between the SMS and location B outside (independent of) the VPN connection?
If so, I remember you must make quite a few exceptions (including manual editing of *.def files on the management server) to keep the SMS traffic outside the VPN…
-Frank
I would say VPN would make sense onbiously, but then as you said, if it fails, you wont be able to communicate. Do you have simple diagram you can send, just to make sure Im not missing anything here.
Best,
Andy
Hi Andy,
Old school pen-and-paper 😀:
-Frank
Hey, its the BEST 😉
K, I think I have better picture now with what you sent. So yes, you can keep the connection between SMS and gw B separate, but Im thinking what would be best way to do this apart from VPN tunnel...
Andy
Hi Andy,
I remember it is quite a hassle (lots of special settings and even editing some .def files on the SMS) to keep only traffic between SMS and the remote gateway (B) outside of the encrypted traffic...
-Frank
It is and truth be told, I always sucked at it lol
Personally, I would not change it myself, unless you are 100% sure what needs to be done. Probably better to verify with TAC.
Best,
Andy
Hi Andy,
I'm afraid TAC will not answer these questions: "did this work before", "NO", "then please go to professional services"...
Thanks for your help anyway. I guess it boils down to fiddling with crypt.def after all :-).
Frank
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY