Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Marquevis
Contributor

VPN Domain and VPN VTI

Hello,

I have a customer with several locally managed SMB gateways. Each SMB gateway has at least 03 VPN DOMAIN. The need arose to configure some VTI VPN. In the documentation, VTI VPN requires that the tunnel is per gateway pair. In the SMB gateway settings I  only find this setting globally. I cannot change this configuration globally, because VPN DOMAIN will be unavailable. I need to find a way to configure VPN DOMAIN and VPN VTI on the SMB gateway, without changing this configuration globally.

16 Replies
the_rock
Legend
Legend

Let me spin up quick smb spark demo and see.

Andy

the_rock
Legend
Legend

Hey, not sure what was the setting you were referring to, but is it possible its below?

Andy

Screenshot_2.png

Marquevis
Contributor

Hello the_rock.

The configuration I'm referring to is the one below.

VPN.png

One of the requirements for configuring VTI is that we use gateway pair configuration.

the_rock
Legend
Legend

My apologies, I cant seem to find that in demo I spun up, but will check again. So you are saying thats global option?

Andy

Marquevis
Contributor

Yes, it is a global configuration.

I need to find a way to do this configuration on each VPN site. Some VPNs will have a subnet pair and others will have a gateway pair.

the_rock
Legend
Legend

So sorry I dont have access to real smb device to test : - (. Is there any setting on specific vpn tunnel that would let you change it or this is the only place?

Andy

Marquevis
Contributor

This is exactly what I'm looking for. It seems to me that there is only this global configuration.

the_rock
Legend
Legend

Got it. Are you allowed to do remote? I really want to try and help with this, because I have a gut feeling might be possible.

Andy

Marquevis
Contributor

Unfortunately, our internal policy does not allow this.

the_rock
Legend
Legend

Understood. So, if you edit any given vpn tunnel, you dont see option to change this individually at all?

Andy

Marquevis
Contributor

Correct, I don't see any option to change this individually.

If this option exists, it must be within some configuration file in the shell.

the_rock
Legend
Legend

Maybe SMB master @G_W_Albrecht might know? Otherwise, I would recommend asking TAC via official case. I will keep checking in the meantime, just bit tricky with demo, as I cant seem to get RDP to open in full screen.

Andy

the_rock
Legend
Legend

I just created bogus tunnel and sadly, cant see option anywhere in the settings similar to below in smart console community.

Andy

Screenshot_1.png

Marquevis
Contributor

The checkpoint instructed me to configure the unnumbered VTI.

https://support.checkpoint.com/results/sk/sk121740

the_rock
Legend
Legend

Thats fine, but not sure if that really addresses your issue specifically?

Andy

the_rock
Legend
Legend

Though, now that I read that sk again @Marquevis , appears it should help, since its related to individual vpn tunnel.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events