Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Shurik
Contributor
Jump to solution

Re-Route Traffic Between Two VPN Tunnels

Hello Colleagues!
 

I need to implement some workaround... I have policy based VPN tunnel with company A and route based (BGP) tunnel with company B. Company A should get to company B through my gateway. 

There are two separate tunnels that works fine, but traffic from A to B doesn't work. I can access both A and B without any problem.

I see traffic from A gets to my gateway, but goes no where... 

Is there a specific configuration that should be done in order to send traffic from A (10.10.10.0/24) to B (10.20.20.0/24) through the same my gateway?

 

Please see attached diagram.

 

Thank you!

0 Kudos
1 Solution

Accepted Solutions
Shurik
Contributor

Thank you! I got it resolved, looks like starting R80.40 we don't need to specify the encryption domain (center gateway), it should be empty group. Once it was removed, it resolved the problem.

View solution in original post

6 Replies
the_rock
Legend
Legend

Make sure routing is enabled for vpn under community setting, tunnel management.

Andy

Shurik
Contributor

Thanks Andy, are you referring to "enable route injection mechanism"? (print screen attached)

If so, should I enable it for the community B or both A and B?

 

0 Kudos
the_rock
Legend
Legend

Im not super familiar with SMB appliances, so not sure if that would be equal to route method on regular vpn community in smart console.

Like below.

Andy

https://community.checkpoint.com/t5/Security-Gateways/Routing-between-VPNs/td-p/90408

0 Kudos
the_rock
Legend
Legend

@Shurik Sorry, forgot to update this. Here is what I was referring to.

Andy

 

Screenshot_1.png

 

VPN Communities - VPN Routing (checkpoint.com)

 

VPN Routing Options

  • To center only . No VPN routing actually occurs. Only connections between the satellite gateways and central gateway go through the VPN tunnel. Other connections are routed in the normal way

  • To center and to other satellites through center . Use VPN routing for connection between satellites. Every packet passing from a satellite gateway to another satellite gateway is routed through the central gateway. Connection between satellite gateways and gateways that do not belong to the community are routed in the normal way.

  • To center, or through the center to other satellites, to internet and other VPN targets . Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.

Shurik
Contributor

Thank you! I got it resolved, looks like starting R80.40 we don't need to specify the encryption domain (center gateway), it should be empty group. Once it was removed, it resolved the problem.

the_rock
Legend
Legend

Good job!

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events