- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Is it possible to use an exclusion group as part of a VPN encryption domain? Or do I have to list out all the network objects that I want and not include the ones I don't want?
Thanks!
I did for one customer whose internal subnet had another devices reachable without VPN (Switches and Routers). On my case, excluding only the hosts (ex. Remote Domain Net 192.168.1.0/24, excluding 192.168.1.2 and 192.168.1.3) It worked without issues.
And you used an exclusion group? Object Explorer -> Network Objects -> Groups -> Group with Exclusions ?
Yes. I configured the exclusion group as encryption domain.
Even worked excluding the external IP of remote gateway, so this way, was not included on encryption domain automatically.
How did you exactly do it ?
You defined the public ip of the gateway as a host object, then included the host object inside a network group object and then excluded it in the excluded section of a network group with exclusions object ?
Evan,
as @KennyManrique mentioned, it is no problem to use a group with exclusions as encryption domain.
I think 80% of our customers are doing this.
Wolfgang
Yes, depending on the size of the excluded hosts/networks it may cause a change in behavior for the size of the subnets proposed in IKE Phase 2, particularly when hosts (/32) are excluded. When exclusions are used, the VPN domain is recalculated into multiple networks/subnets to exclude the desired addresses. You can use tools like Danny Jung's VPN Domain One-liner to see this in action:
Groups with exclusions have many limitations one should be aware of. (sk97246, sk101506, sk107543, sk107417, ..)
I've also mentioned this in my article about Properly defining the Internet within a security policy.
Hello Dany,
the most important thing when working with Encryption Domains and Exclusions is this SK sk39679
you have to switch to "one tunnel per gateway pair" as this SK sk39679 states
best regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY