Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ibrown
Participant
Jump to solution

Backup over vpn

Hello Everyone,

odd question this, but I've not found a solution as yet.  I have several Quantum spark appliances around the world in branch offices, connected to the main office via vpn.

 

I schedule periodic backups but these come out via the external (ie primary) interface address and don't decrypt and route correctly at the main office end. Is there a way to force an interface for the ftp traffic ?

 

Currently I send to an externally facing SFTP server, but ideally I'd come via the vpn.

 

Any thoughts ?

 

Thanks

Ian

0 Kudos
2 Solutions

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Locally or centrally managed?

In advanced settings there is an option to source locally generated traffic from the internal address as an option.

"Use Internal IP address for encrypted communications from the local gateway"

Other options exist but may add unnecessary complexity in configuration 

CCSM R77/R80/ELITE

View solution in original post

PhoneBoy
Admin
Admin

The procedure is different for centrally managed SMB appliances: https://support.checkpoint.com/results/sk/sk119415 

View solution in original post

7 Replies
Chris_Atkinson
Employee Employee
Employee

Locally or centrally managed?

In advanced settings there is an option to source locally generated traffic from the internal address as an option.

"Use Internal IP address for encrypted communications from the local gateway"

Other options exist but may add unnecessary complexity in configuration 

CCSM R77/R80/ELITE
ibrown
Participant

Hi Chris, this is a spark 1570 R81.10.08, and centrally managed. However the only option in advanced I can see is '
DHCP relay - Use internal IP addresses as source'

0 Kudos
PhoneBoy
Admin
Admin

The procedure is different for centrally managed SMB appliances: https://support.checkpoint.com/results/sk/sk119415 

ibrown
Participant

Brilliant thank you ! Tested and works

0 Kudos
ibrown
Participant

Anyone know if this is possible on a 3000 appliance ?

I have three 3200s running R81.20 - Build 011

They are centrally managed so the setting is not available and the kernel setting does not seem available

Set operation failed: failed to get parameter fw_enc_conns_use_internal
set: Operation failed
/bin/cpfw_start: line 12: 29398 Killed $FWDIR/bin/fw "$@"

0 Kudos
PhoneBoy
Admin
Admin

This is specific to SMB.
I don't believe it has an equivalent on regular gateway but perhaps a specific NAT rule will achieve the desired result?

0 Kudos
ibrown
Participant

Thank you, I shall try that.

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events