- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Checkmates,
R81.10 Gateway
I have two sites A and B which is connected by IPsec VPN, in site B I have my SNMP application with a private IP. I wanted to monitor my Check Point firewall in site A with it's WAN IP which is used for VPN tunnel.
I tried doing it but failed multiple times.
1> Checked for packet captures >> negative
2> Checked for kernel debugs >>negative
Can anyone help me on this please, I can't exclude snmp service under vpn because it's a weak version that we are using.
+PFA for your reference.
=======
WR,
FH
Have you tried exclude the SNMP from the Tunnel?
But this is not the safest setup, but I think you know it.
Akos
UPDATE: you wrote, you can't exclude it. ACK 🙂
What if you set the SNMP config for an IP which is in the ENC_DOM and reachable from site. Create a small VLAN with /29 prefix, and it is avaialable on the GW _only_ (no connection to the intranet) The routing will direct the traffic to that IF -> it should work, but not a beautiful solution.
Hi @AkosBakos ,
Thanks for your quick update.
Can you please explain it, do you mean to create a Vlan on the gateway and add that ip in the encryption domain of the vpn??
Use that ip for snmp monitoring ?
====
WR,
FH
Hi,
This is only an idea, unfortunately I can't test is yet. Please be cautious.
This is a simple interface modificationm and a VPN Domain extension
So I would create an IF which exists only on the GW (you need to discuss with the network team for the availabe IPs and VLANs)
You will query the GE on this interface (in this case 192.168.99.1)
Then and it to the ENC_ DOM (VPN Domain)
You need to add it both sides.
Create the neccesary Access Rules.
When the packet arrives to the GW, because the newly created LAN is a connected LAN, the route will direct to that interface (192.168.99.1) the trafic.
Akos
The WAN IP is automatically included in the encryption domain, which means the traffic will likely be encrypted.
fw monitor should show you if the traffic is being encrypted/decrypted correctly or not.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY