New to CheckPoint firewalls and and helping troubleshoot an issue we're having on a new site-to-site VPN we have setup between us and JAMF for a MDM VPN solution. Everything is working properly except for one server that we're trying to access and the only unique thing about this server is it's in one of the DMZs hanging off the firewall. Everything else is on the internal network. When I try and access the server over the tunnel, I get "According to the policy the packet should not have been decrypted" and it drops the packet.
Some basic info:
Gateways running Gaia R80.40.
Remote VPN Endpoint: 78.50.44.10
Local VPN Endpoint: 60.40.89.10
Trouble Server Real IP: 192.168.10.50
Trouble Server NAT IP: 60.40.89.50
VPN Domain: Main_Encrypt_Group
For the VPN community, the center gateway is the one I'm working on and the VPN Domain is a generic/general group that looks to be applied to all VPN communities and the gateway. VPN routing is set to 'to center and to other satellites through center.' NAT is disabled under advanced. One VPN tunnel per gateway pair is checked.
One theory I have is that the server I'm having issues with is not in the 'Main_Encrypt_Group' and is why it's not staying encrypted. However, this group is used for all other VPN communities and I was hesitant to add the DMZ server to this group without knowing the impact.
Am I able to change my JAMF VPN tunnel to a different group without impacting anything? My thought was to clone the existing VPN Domain Group and create a 'JAMF_Encrypt_Group' and put the extra server in the group. I then noticed under the 'Gateway Cluster Properties' that Under 'Network Management/VPN Domain' there is a 'set specific VPN Domain for Gateway Communities'. Right now they're all set to 'according to the gateway'. Is it as simple as just clicking on the JAMF one and then "Set" and choose my new VPN Domain Group? It feels like that is what the solution might be but since I'm relatively new, I wanted to run it by here first.
Update:
Also, forgot one thing.. would I add the real IP AND the NAT IP or just the real? We tried connecting both ways but got the encryption error.