Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
abihsot__
Advisor

How to update RA encryption domain dynamically?

Hello,

 

Gateway is R80.40 and I have bunch of endpoint security VPN clients.

hub mode is NOT enabled. 

For example I want that checkpoint.com would be part of encryption domain. The problem is that I cannot add domain or any other clever object into encryption domain. Only host or network objects allowed.

 

Do you have any ideas how it could be implemented easily? Maybe someone already got script working in action?

I was thinking of resolving domain to IPs and then feeding them to API to create objects and pushing the policy. On next client connect new topology should be downloaded.

0 Kudos
4 Replies
_Val_
Admin
Admin

I think you have already answered your own question. 

Now, why would you need to add a domain to the encryption domain of your VPN in the first place? Those network objects are supposed to be internal.

0 Kudos
abihsot__
Advisor

Between black (Hub mode) and white (internal network), grey color exist, where you might want to do it only for certain applications. For example where restriction is based on HQ IP. Because IP of the domain can change, ability to add domain object inside encryption domain would be extremely useful. 

I hope it would be of interest for Checkpoint to implement it at some point.

0 Kudos
PhoneBoy
Admin
Admin

The closest thing we have is: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
There is also a customer release that allows for Updatable Objects and Dynamic Objects to be used for the encryption domain.
Please check with your local Check Point office for further details.

abihsot__
Advisor

Yes, I am aware of this SK and it is indeed nice workaround playing with exclusion list.

Thanks for heads-up, it was worth describing my problem here. I'll check with local office what they have.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events