Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ryan_Ryan
Advisor

R81.10 VPN encryption domain override

Hi,

 

I have used the encryption domain override on both the center and remote gateways in two different vpns on two r81.10 gateways. Everything worked fine to my Cisco router on the other end with matching encryption domains (I am using mainly /32 host addresses).

 

However I then noticed something was not right, when I tried to send traffic in the other direction, sourced from behind checkpoint to the far end it did not work, in the checkpoint logs it said no SA has been established, although there was a matching SA for these host pairs as I could run the same traffic in the opposite direction without issue.

I turned debugging on the Cisco phase 2 and found the checkpoint was trying to propose a  /16 mask for the local network address which is in the gateways encryption domain, the /16 was not in the override, I tested by temporarily adding a /16 to the enc domain on the cisco side and guess what it worked.

 

Is there any reason why checkpoint would not use its override domain for outgoing traffic?

0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events