cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

Route-based VPN Proxy ID 0.0.0.0/0?

Jump to solution

Hi CheckMates,

Am I correct in understanding that for route-based VPN with unnumbered interfaces the only available option is universal tunnel, so proxy ID of 0.0.0.0/0?

If not, can anyone tell me how you're supposed to get the proxy ID right?
Kind regards,

Nik Bloemers

 

0 Kudos
1 Solution

Accepted Solutions
Highlighted

Re: Route-based VPN Proxy ID 0.0.0.0/0?

Jump to solution

Correct, a route-based VPN tunnel has to be universal since we do not know ahead of time what traffic IP routing will dump into the VPN tunnel; set one tunnel per gateway pair in the VPN Community object to get 0.0.0.0/0's.  With a domain-based VPN we do know exactly what IP addresses will appear in the tunnel based on the static VPN domain definitions.

Book "Max Power 2020: Check Point Firewall Performance Optimization" Third Edition
Now Available at www.maxpowerfirewalls.com

View solution in original post

1 Reply
Highlighted

Re: Route-based VPN Proxy ID 0.0.0.0/0?

Jump to solution

Correct, a route-based VPN tunnel has to be universal since we do not know ahead of time what traffic IP routing will dump into the VPN tunnel; set one tunnel per gateway pair in the VPN Community object to get 0.0.0.0/0's.  With a domain-based VPN we do know exactly what IP addresses will appear in the tunnel based on the static VPN domain definitions.

Book "Max Power 2020: Check Point Firewall Performance Optimization" Third Edition
Now Available at www.maxpowerfirewalls.com

View solution in original post