- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good morning,
I have two checkpoint 750 and 730 devices connected to each other using VPN S2S.
IP traffic using VPN works without problem. I can access devices on the LAN from either side.
From the CP750 side, I have an Exchange Server 2019 ST server.
When Outlook is on the LAN, the CP730 cannot connect to Exchange Server 2019 because it does not send DNS queries via VPN.
How to configure the CP 750 and 730 for DNS queries to be sent over the S2S VPN tunnel.
There is an advanced setting which if enabled will provide the behaviour as your describing.
"Do not encrypt local DNS requests"
Worth checking before exploring elsewhere.
In the advanced settings, I have set the following options:
Global VPN Site to Site settings - do not encrypt local DNS requests - TRUE
I set the setting as always about CP730 and CP 750.
Even so, I still don't have DNS traffic over the S2S VPN. You can see in the logs that it is encrypted.
The other advanced option that may apply is:
"Do not encrypt connections originating from the local gateway"
Failing this if all other VPN parameters check out and you're on the latest build of R77.20.87 I would discuss it further with TAC.
In each of the configuration pages, for these two settings to be set to TRUE.
Screen in the appendix.
I don't know if it matters, but the S2S VPN connection is made using certificates.
Even though you select the option that it does not encrypt DNS traffic it does otherwise.
The log shows that traffic from the CP730 LAN is blocked on the CP 750 side.
Maybe a rule in the firewall needs to be created?
Are both centrally managed? If so, check option in global properties "accept domain name over..."
I started unencrypted DNS traffic over VPN.
In the S2S VPN settings I checked the option: "Allow traffic to the internet from remote site through this gateway."
I applied the setting to both Checkpoint devices.
Do Not Encrypt Local DNS Requests of TRUE means that DNS requests won't be encrypted (sent over VPN).
What happens when you make it FALSE?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY