- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Check Point RnD informed us, that there is an important limitation for VPN Site-to-Site tunnels to consider:
The only tunnel sharing method that supports a mix of network object types (hosts, ranges, networks etc.) is "tunnel per Gateway pair". "tunnel per each pair of hosts" must include host objects only and "tunnel per subnet pair" must include network objects only. Anything else is considered a misconfiguration.
That one should really be put in to a "info" box on each option here.
Always struggling with more advance vpn boxes and ends up using user.def file to make sure its how i want to to be configured.
I know Phoneboy mentioned in one of the posts that there are lots of new options coming for VPN settings in smart console starting R82 version, so this might be one of them, we shall see : - )
Andy
I hope they fix so you can see standard issues in the log aswell and dont need to actually debug the traffic to figure out you sending the incorrect subnetmask or similar 🙂
That would be super useful 🙂
In 15 years, I never knew of that. But, in all honesty, maybe that never used to be an issue in old versions, cant recall now : - )
Thanks for sharing!
Andy
Just checking, do we know how these settings affect dynamic objects? When a dynamic object is added to a gateway it can be configured to include individual host IPs, network ranges, or both.
To the best of my knowledge, dynamic objects cannot be added to an encryption domain.
Technically, you can, but policy will fail : - )
This I am aware of, but it must be done as described or it will not work 🙂
Having "One VPN tunnel per subnet pair" will let you establish tunnels between HOST<>NET and NET<>NET.
Thats debatable, does not always work. I find that tunnel per gateway pair will do that 100% of the time.
Andy
One tunnel per gateway is ideal... It just establishes a single 0.0.0.0/0 tunnel.
Thats pretty much generic for any vendor, but yes, thats indeed true.
For a Host object in the domain, the SA will attempt use an exact IP or in some cases I have seen it convert the IP into a /24,
While the Tunnel management is set to Subnet pair.
so if the host object is to a Peer subnet, the SA will appear like this:
| My TS: 10.140.250.1
| Peer TS: 192.168.1.0/24
or like this
| My TS: 10.140.250.0/24
| Peer TS: 192.168.1.0/24
However,
You can have it use a /32.
so if you use a network object that is a /32 instead.
you will get a SA like:
| My TS: 10.140.250.1/32
| Peer TS: 192.168.1.0/24
================
You may also be able to force it to the exact subnet you wish with user.def.FW1 edits.
But I would recommend to use Network objects for Subnet Pairing.
In old days on CP and we are talking probably 15 years ago (or more), it was so annoying to have to always change guidbedit setting(s) for supernat, as it would always try to present largest possible subnet, specially with Cisco VPN tunnel.
Glad thats sorted out in R80 + : - )
Andy
Yes, and now with R81, Permanent Tunnels are set tp DPD for Interoperable devices be default.
I was very happy with that change!
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
31 | |
17 | |
5 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY