- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello all!
I have a simple question but I can't clarify this point by googling.
I have box under R77.30 and IPsec community based VPN.
The IPsec is a legacy solution and I need to migrate some networks to L3VPN which available via 802.1Q subinterface on firewall.
By now, I use an aggregated prefix 10.0.0.0/8(at remote site) throught IPsec. I need migrate 10.1.1.0/24 to L3VPN.
Can I just make new static through L3VPN subinterface or I should change IPsec settings(exclude10.1.1.0/24 from encryption domain or etc.)?
The general point is where exactly the crypto policy is applyed.
Thanks in advance.
Regards.
Hello PhoneBoy! Thanks for your answer.
By now, I have remote encryption domain which contains 10.0.0.0/8. I would like to switch traffic for remote network 10.1.1.0/24 through L3VPN. What should I reconfigure in sense on encryption domains?
Regards, Andrey.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY