- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
I have a customer with several locally managed SMB gateways. Each SMB gateway has at least 03 VPN DOMAIN. The need arose to configure some VTI VPN. In the documentation, VTI VPN requires that the tunnel is per gateway pair. In the SMB gateway settings I only find this setting globally. I cannot change this configuration globally, because VPN DOMAIN will be unavailable. I need to find a way to configure VPN DOMAIN and VPN VTI on the SMB gateway, without changing this configuration globally.
Let me spin up quick smb spark demo and see.
Andy
Hey, not sure what was the setting you were referring to, but is it possible its below?
Andy
Hello the_rock.
The configuration I'm referring to is the one below.
One of the requirements for configuring VTI is that we use gateway pair configuration.
My apologies, I cant seem to find that in demo I spun up, but will check again. So you are saying thats global option?
Andy
Yes, it is a global configuration.
I need to find a way to do this configuration on each VPN site. Some VPNs will have a subnet pair and others will have a gateway pair.
So sorry I dont have access to real smb device to test : - (. Is there any setting on specific vpn tunnel that would let you change it or this is the only place?
Andy
This is exactly what I'm looking for. It seems to me that there is only this global configuration.
Got it. Are you allowed to do remote? I really want to try and help with this, because I have a gut feeling might be possible.
Andy
Unfortunately, our internal policy does not allow this.
Understood. So, if you edit any given vpn tunnel, you dont see option to change this individually at all?
Andy
Correct, I don't see any option to change this individually.
If this option exists, it must be within some configuration file in the shell.
Maybe SMB master @G_W_Albrecht might know? Otherwise, I would recommend asking TAC via official case. I will keep checking in the meantime, just bit tricky with demo, as I cant seem to get RDP to open in full screen.
Andy
I just created bogus tunnel and sadly, cant see option anywhere in the settings similar to below in smart console community.
Andy
The checkpoint instructed me to configure the unnumbered VTI.
Thats fine, but not sure if that really addresses your issue specifically?
Andy
Though, now that I read that sk again @Marquevis , appears it should help, since its related to individual vpn tunnel.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
7 | |
3 | |
3 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY