- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a management server which communicate with a remote gateway via Internet.
Between them there is a vpn site to site.
I would like to know which is the best practics for excluded services configuration on this vpn, like fw1_logs, cpd, cpmi, etc.
I would like to reach the gateway remotely even if the vpn is down and check logs as well.
If VPN is down, then you just need to make sure routing/rules are there.
Andy
I don't know the exact situation (peers are CP it 3rd party), but when I set GW managened on its external IP.
So it was someting like that:
site1 (management) <-- VPN tunnel --> site2 (VPN peer IP is the same as the MGMT IP that reaches the Management)
This two SK helped me a lot:
After enabling 'Exclude gateway's external IP addresses from the VPN Domain' VPN Tunnel is down
https://support.checkpoint.com/results/sk/sk180716
VPN Site-to-Site with 3rd party
Scenario 3 - Implied inclusion of Check Point Security Gateway's / 3rd party VPN Peer's interfaces
https://support.checkpoint.com/results/sk/sk108600
The sk108600 is not trivial, read carefully before do anything.
I hope it helps.
Akos
By default, SIC related traffic does NOT go through the VPN tunnel.
Hi,
You mean that when the flow is SMS - GW1 - VPN - GW2 the SIC wont’t be tunnled?
I found this thread:
https://community.checkpoint.com/t5/Security-Gateways/Allow-Management-over-VPN/td-p/192915
I had memories about the exclusion in this scenario.
Maybe it woudn’t be necessary…
akos
Correct, SIC related traffic is accepted by implied rules before VPN is applied.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY