- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone, does anyone know if it is possible to configure a site-to-site VPN between two Check Point R81.20 gateways that are within the same subnet? The client has two data centres linked at layer 2 and want an encrypted tunnel, but at layer 3 it's the same subnet, with one gateway at either end of the link. Unfortunately I do not have sight of the configuration as it's in a secure environment but it seems that the tunnel is not coming up and I was wondering if it is simply never going to work without other changes (e.g. using different subnets) or whether to continue diagnostics work. Thanks.
Yup...just assign empty group as enc. domain on both fws.
I believe not. To send the traffic encrypted from one site to another your gateways must work as Layer 3 routing device.
If your datacenter is connected via Layer 2, why not using encryption features of the Layer 2 devices like MACSec?
Or as an idea you can create a VXLAN tunnel for your Layer 2 subnet see sk170014 - Virtual Extensible LAN (VXLAN) Configuration Guide
Im fairly sure we got this working before the way I mentioned.
As in a collection of networks behind one firewall, a different collection of networks behind the other firewall, and the two firewalls are connected with no routers between them? Works fine. VPN termination functionality is just traffic which rides on top of routing functionality. If they can ping each other, they can negotiate IKE and IPSec.
If the networks behind each firewall overlap, it won't work, but that has nothing to do with the topology of the environment between them.
True that!
Thank you for all your comments - looks like more diagnosis on the underlying issue is required.
Let us know how it gets solved...cheers.
If you configure S2S and both sites have the same subnet, you need to add a NAT rule to translate both your local subnet and the remote subnet on the other site.
Description below:
In the Communities settings, you still define the actual local and remote subnets. Then, you need to create two different subnets for the NAT configuration.
At this point, both sites must allow firewall rules for those NAT subnets instead of allowing the real subnets.
After doing so, each site will only see the other’s NAT subnet, not the real IPs.
That's correct if the gateways have the same subnet behind them. That doesn't sound like what's going on here. This environment sounds like a normal VPN topology, except instead of the Internet with a bunch of routers between the firewalls, it's a switched path (or a pseudowire or something similar).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 17 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY