- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a VPN community for a B2B connection set up, with their VPN Domain containing a /21, that all works fine.
There is 1 IP address in that /21 that is for a public website that we don't want to to route over the VPN, and I'm trying to figure out how to exclude it from being routed over that VPN.
I've tried setting up a NAT rule to translate the source to an different IP than the one used for that community, but it still attempts to route over the VPN.
I've also tried setting up a static route, setting the next hop to the IP used as our default gateway.
How would I exclude an address from being routed thru that domain?
Thanks Danny! The SK for crypt.def was a little daunting and not clear how to specifically exclude an address, but that posts solution explains it very well!
I also just discovered that exclusion group objects exist. Do you know if using an exclusion group would cause any issues if I use that as the Satellite VPN domain?
It would be a simpler approach and be easier to share with my other techs.
As this article describes, groups with exclusions may have issues when used with VPN encryption domains. It might work, just test it and keep a close eye on the calculated result. I understand you are looking for an easy solution. However, your task it not easy by design. You could also create a group containing multiple network objects describing your /21 network without that single IP address in order to use that manually crafted network group as your new encryption domain. However, keep in mind Check Point performs supernetting by default, so you might still end up with a /21 encryption domain. That's why crypt.def is your friend.
I really appreciate the in depth response! I'll experiment with the exclusion group, but it looks like I'll likely need to go with defining an exclusion within crypt.def.
I'll try and update this post with my results once I've tested, for anyone that might stumble upon this post in the future.
I use this
> You could also create a group containing multiple network objects describing your /21 network without that single IP address in >order to use that manually crafted network group as your new encryption domain.
+ force the firewall to use a specific subnet editing user.def.FW1
TAC told me that exclusion group as encryption domain are not supported even if you can use them from Smart Console
>- Exchanged the network group with exclusions(not supported in the encryption domain) with a standard network group
Exclusion groups ARE supported for Remote Access VPN: https://support.checkpoint.com/results/sk/sk167000
However, that’s relatively recent and for the specific use case it was designed for (Remote Access).
ok , i used them in s2s vpn
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY