- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello CheckMates
I would like to request some clarification regarding the Star VPN Routing option "To center or through the center to other satellites, to Internet and other VPN targets" (3rd option). When I have the option enabled, it becomes possible for all Center Networks, even the ones not part of the Center-EncDom on the Center Gateway to reach all Satellite EncDom Networks. It will match the ACL and enter the VPN Tunnel, when to my current understanding it is not meant to. Could anyone please clarify as to why this is?
See a small summary of my configuration below, all devices are OpenServers running R81.20 with JHF 53.
This is an official explanation of how those settings work.
Andy
To center only . No VPN routing actually occurs. Only connections between the satellite gateways and central gateway go through the VPN tunnel. Other connections are routed in the normal way
To center and to other satellites through center . Use VPN routing for connection between satellites. Every packet passing from a satellite gateway to another satellite gateway is routed through the central gateway. Connection between satellite gateways and gateways that do not belong to the community are routed in the normal way.
To center, or through the center to other satellites, to internet and other VPN targets . Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.
"To center, or through the center to other satellites, to internet and other VPN targets" means route ALL traffic through Center gateways (e.g. Internet-bound traffic or traffic to other VPN gateways).
It's acting as expected.
This is an official explanation of how those settings work.
Andy
To center only . No VPN routing actually occurs. Only connections between the satellite gateways and central gateway go through the VPN tunnel. Other connections are routed in the normal way
To center and to other satellites through center . Use VPN routing for connection between satellites. Every packet passing from a satellite gateway to another satellite gateway is routed through the central gateway. Connection between satellite gateways and gateways that do not belong to the community are routed in the normal way.
To center, or through the center to other satellites, to internet and other VPN targets . Use VPN routing for every connection a satellite gateway handles. Packets sent by a satellite gateway pass through the VPN tunnel to the central gateway before being routed to the destination address.
Thank you for the official explanation. However, PC-C is a part of the Center GW, not defined in the Encryption Domain that is able to reach PC-B, which is a satellite host part of the Satellite Encryption Domain. When I read this original explanation my assumption was that it would be the case that all traffic sent by the satellite gateway would be encrypted, yet it is the Center gateway that initiates this connection. Hence my question.
Am I then to assume that this will then apply for both Center and Satellite connections to be forced to cross that VPN Tunnel when an ACL is matched?
Thank you for your time!
Then why not stay with the second option ?
"To center, or through the center to other satellites, to internet and other VPN targets" means route ALL traffic through Center gateways (e.g. Internet-bound traffic or traffic to other VPN gateways).
It's acting as expected.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 20 | |
| 16 | |
| 7 | |
| 6 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY