Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Evan_Fisher
Participant

Encryption Domain with Exclusion Group

Is it possible to use an exclusion group as part of a VPN encryption domain? Or do I have to list out all the network objects that I want and not include the ones I don't want?

 

Thanks!

0 Kudos
9 Replies
KennyManrique
Advisor

I did for one customer whose internal subnet had another devices reachable without VPN (Switches and Routers). On my case, excluding only the hosts (ex. Remote Domain Net 192.168.1.0/24, excluding 192.168.1.2 and 192.168.1.3) It worked without issues.

0 Kudos
Evan_Fisher
Participant

And you used an exclusion group? Object Explorer -> Network Objects -> Groups -> Group with Exclusions ?

0 Kudos
KennyManrique
Advisor

Yes. I configured the exclusion group as encryption domain.

Even worked excluding the external IP of remote gateway, so this way, was not included on encryption domain automatically.

0 Kudos
Nikolaos_Liakop
Explorer

How did you exactly do it ?

You defined the public ip of the gateway as a host object, then included the host object inside a network group object and then excluded it in the excluded section of a network group with exclusions object ? 

0 Kudos
Wolfgang
Authority
Authority

Evan,

as @KennyManrique  mentioned, it is no problem to use a group with exclusions as encryption domain.

I think 80% of our customers are doing this.

Wolfgang

0 Kudos
Maarten_Sjouw
Champion
Champion

We did use it also, but found some weird behavior with it, it stopped working based on Network to Network and started working with host based tunnels instead.
Must say this was with R77.30 gateways.
Regards, Maarten
0 Kudos
Timothy_Hall
Champion
Champion

Yes, depending on the size of the excluded hosts/networks it may cause a change in behavior for the size of the subnets proposed in IKE Phase 2, particularly when hosts (/32) are excluded.  When exclusions are used, the VPN domain is recalculated into multiple networks/subnets to exclude the desired addresses.  You can use tools like Danny Jung's VPN Domain One-liner to see this in action:

https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-to-show-VPN-topology-on...

 

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
Danny
Champion Champion
Champion

Groups with exclusions have many limitations one should be aware of. (sk97246, sk101506, sk107543, sk107417, ..)

I've also mentioned this in my article about Properly defining the Internet within a security policy.

0 Kudos
Thomas_Eichelbu
Advisor

Hello Dany, 

the most important thing when working with Encryption Domains and Exclusions is this SK sk39679

you have to switch to "one tunnel per gateway pair" as this SK sk39679 states

best regards

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events