- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Is it possible to copy all firewall, QoS rules from a simplified policy to a traditional policy?
This exact problem (and solution) is here: Excluding subnets in encryption domain from accessing a specific VPN community
Traditional Mode policies have been discouraged since at least NG (R5x) versions.
In R80, the ability to create new Traditional Mode policies was removed and isn't coming back.
What's the real problem you're trying to solve?
Let's find a way to solve that in a way that doesn't involve Traditional Mode policies.
Hello Dameon,
Thank you first.
I have a IPsec VPN established and I need to forward all Internet traffic to this tunnel, but only one internal subnet must be affected on tihs.
How can I do this using communities?
This exact problem (and solution) is here: Excluding subnets in encryption domain from accessing a specific VPN community
Thank you Dameon.
I want to send to that tunnel only requests from 192.168.1.0/24 going to the Internet (example);
Thinking on that, I will need to exclude all my internal subnets going to the Internet, example:
// // User defined INSPECT code // vpn_exclude_src={<192.168.1.1,192.168.1.254>}; vpn_exclude_dst={<I need to put all Internet IPs here?>}; #ifndef IPV6_FLAVORipv #define NON_VPN_TRAFFIC_RULES ((src in vpn_exclude_src) and (dst in vpn_exclude_dst)) #else #define NON_VPN_TRAFFIC_RULES 0 #endifSo, I'll need to put all Internet IPs on vpn_exclude_dst?
Correct.
All IPs can be represented using the range specified in the All_Internet object, which is <0.0.0.0,255.255.255.255>.
Thanks
And a curious thing: why Check Point does not put this kind of configuration in the Smart Dashboard?
I personally hadn't heard of this specific use case before.
Uhmmm... but this case does not sounds like a not common case.
If it was a common case, we will not have a SK to this kind of situation...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY