Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
IT_Eng
Participant

Site-to-Site VPN with overlap subnets between communities

Hello Mates,

 

We have an existing community with a tunnel to Palo Alto A with subnet 10.16.0.0/15 behind it.

We need to create a new tunnel in a different community to a Palo Alto B with a subnet of 10.16.100.0/24.

The tunnel to tunnel B is not even initiating IKE, all the traffic is going to the existing tunnel to Palo Alto A.

I know that the proper subset (as called by Checkpoint) is not supported in general, but is it not clear which side the proper subset is referred to.

The only option I see is a route-based VPN for the new tunnel. But I thought I will ask here before if there is something different to try.

 

SMS and gateway os R81.10

0 Kudos
5 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events