- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all, i have a strange configuration for a small network in a remote location the setup is like this:
[Smart Console]--[QF 9000 series]--((Internet))--[LTE Modem]--[SMB]
I have a route based VPN between [QF 9000 series]-[SMB] and policy installation work by [SMB] policy fetch it's not a direct installation, [SMB] report error in smart console since LTE Modem don't have a public IP address, [SMB] is a DAO object, I tried to set IP address of VTI interface in smart console but it still don't work, when i use the DAO object i see the IP of [LTE Modem] in "Device & License Information".
I'm also trying to set a NAT in [QF 9000 series] to expose a device behind [SMB] but I will make some more tries before try with another post.
Thanks in advance for any support.
Can you please share some diagrams, versions in use, any other details you may want us to know?
SMB have "Dynamic Address" checked and "SIC" established.
Log forwarding from SMB to smart console works
If I click in "Device Information" i see "LTE Router" DHCP WAN IP.
VPN Community don't exclude any service.
Here list of IPs, I have also attached a schema.
| WAN | LAN | VTI | |
| QF 9000 | Public IPs | 192.168.200.1/24 | 10.254.254.1 |
| LTE Router | DHCP | 192.168.178.1/24 | - |
| SMB | 192.168.178.2/24 | 192.168.220.1/24 | 10.254.254.2 |
In general you do not want management traffic to traverse the VPN.
Presumably you've exposed your MGMT via NAT so it can be reached remotely?
MGMT have a NAT to be reachable from external allowed IPs and this allow log forwarding and policy fetch from SMB, I would like to have MGMT to show device health.
I don't believe I've seen this work for DAIP gateways.
I would check with TAC to see if this is expected.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY