Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gcarella
Participant
Jump to solution

Traffic to public peer it's always encrypted in VPN community tunnel

Hi all,

 

I would like to discuss with the community about a strange behavior that I'm experiencing on Check Point security gateway.

I state that I'm quite new with Check Point and I have less than 1yr of hands-on experience on this products. Therefore I often have doubts about topics or features that maybe are obvious to many.

Anyway what it's struggling me from some time is that when for example I launch a ping to a public peer of an active VPN community (star), the traffic is encrypted and sent over that tunnel instead to travel unencrypted towards internet interface.

For me this is a strange behavior I'm expecting that traffic shall go directly on internet as it happens on other VPN S2S implementation that I manage with other vendors.

The issue is present on Check Point SecGateway and CloudGuard, both with R80.30. 

 

Any idea why this happens?

 

Thanks,

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

View solution in original post

4 Replies
PhoneBoy
Admin
Admin

The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

gcarella
Participant

Thanks a lot.

There is a specific reason why the Secure Gateway includes public peers in the encryption domain?

0 Kudos
PhoneBoy
Admin
Admin

No idea but it has been the default behavior pretty much since the product supported VPN.

0 Kudos
the_rock
Legend
Legend

@PhoneBoy is 100% correct. Interfaces would be technically part of vpn domain by default, but if you follow the sk mentioned, you should be able to exclude them.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events