- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
How is the complete Definition of the Object "Internet" in SmartConsole ?
as i already found it should include Traffic which is going through an Interface which is marked as external.
Now my Problem:
we have a VPN to a Customer.
The Website of the Customer is hosted on the same IP like the Peer for VPN.
Somehow the Rule for Internet access is now not used and the Traffic gets Blocked in the Cleanup Rule.
So now my Question:
What is really included in the Object "Internet" ?
Or am i forced to use !RFC1918 to simply include every IP except Private?
Hi,
Trying to understand your issue. You have a S2S vpn with a remote peer (one of your customers). This customer is also hosting on the same ip used for VPN their web site. And you can't reach their web site anymore from internal network.
So CustomerIP = IP registered in the S2S vpn = IP of their web site.
S2S VPN: working fine.
Http (or https) to CustomerIP from your internal network doesn't work.
Right?
Thanks,
Have you already handled sk108600 scenario 3?
"Internet" means traffic routed through the external interface that doesn't go through a VPN.
Gateway IP is always included in the encryption domain by default unless it's disabled (sk108600 option 3), which is probably why it is getting handled via a different rule.
Thanks for the fast reply.
So if i understood correctly, i have the following options to solve this.
1. sk108600 scenario 3 --> edit "crypt.def"
2. use of a normal Network Group like !RCF1918 which shouldn't care if its also a Peer IP or not.
Both should work if i get it right ?
The only way to prevent the gateway from including it's own IP in the encryption domain is editing crypt.def OR, if this is an option (believe this is only possible on R81.20):
Not sure what you mean by your second point.
However, it would help tremendously if you could show what rules are matching (what you expect versus what actually is).
Phoneboy explained it perfectly.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY