- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I have two Gateways X and Y.
I have 3 internal networks on X that if going to internet i want to route via Y. The moment i enable it my SMS looses connectivity to X (externally managed). But my internal networks on X gets routed thru Y. So thats works.
I can ssh to the internal mgmt address of X (s2s vpn). Everything works but my X firewall itself cant reach internet or my SMS.
In the vpn domain between X and Y i have only specified the 3 local networks of X. So i really dont understand why the firewall looses connectivity?
See attached pictures.
100% its supported, I know multiple customers that did it in different versions.
Do the zdebug on the firewall and see why its getting dropped...or look at the logs on the management, it would give you a good idea, for sure.
its not getting dropped.
The problem is that my X firewall has 20 networks, 17 of them should go through the regular default route and 3 networks should go through the VPN tunnel and out to the internet that way. When I enable VPN routing, all 20 networks go over the VPN tunnel despite the other 17 not being specified in the VPN domain. The X firewall is also trying to go through the VPN tunnel when, for example, I ping 1.1.1.1 from the CLI.
Version/JHF level of gateways?
Are you using Route-Based VPN or Domain-Based VPN?
I suspect you'll need a combination of Route-Based VPN and PBR to achieve this goal.
Something similar to the following albeit with different criteria: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Hi Phoneboy,
Thanks for you reply. Im now able to access internet thru my tunnel, i had to uncheck my external to be in included ip in the VPN Domain under Network Management on the gateway, im running R81.20 MGMT and R81.10 take 81 on gates. However now im facing the issue that i need to NAT incoming external traffic back in the tunnel to a internal host. I see that i tries to NAT the traffic to the correct host but it does not go in the tunnel, the VPN domains are correctly setup.
Yes, thats nice option included in R81.20 version, to exclude external IP from enc domain in smart console, which was never there before, had to be done in crypt.def file I believe. Regardless, for your other issue, make sure NAT option is not disabled within the VPN community setting (last option on the left) and if so, create manual nat rule to reflect needed changes.
Hi the_rock,
Thank you for your input, and sorry for my late answer. I talked with Checkpoint TAC and they referred do this,
Destination NAT traffic not encrypted when the original destination included in the NATting gateway ...
I setup a route-based VPN but i couldnt get PBR to work even tough it should be supported. So i kind of gave up on this solution.
100% its supported, I know multiple customers that did it in different versions.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY