- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello Mates,
have here a R81.10 T22 with a S2S VPN to 3rd Party but I cannot see the route to the target encryption domain in the route table of the OS or in Gaia. The VPN works fine though.
Is this by design or do I miss an option?
Regards
David
You can't redistribute that directly since routes in the vpn_routing table are not "real" routes that exist in the Gaia OS that OSPF can see.
If you are using at least R81, check out NAT Pools which should allow redistribution. Here is the relevant page from my Gaia 3.10 Immersion self-guided video series:
Is this a route based or policy based VPN?
We define in the VPN communities the encryption domains for each site so i guess it's domain based.
I haven't found a quick answer about the difference of each types (route based, policy based, domain based) 😅
Then you will not find them in the routing table. You can try with the following command in the Expert mode:
fw tab -f -t vpn_routing -u
ah yes there i see it...
Any ideas how i can use this route now to redistribute it via OSPF?
I mean it works when I manually add an static-route for the neeeded route and add it to a route-map but this is an equal ugly solution as the output from "fw tab -f -t vpn_routing -u" 😥
In my opinion, after you need dynamic routing the best way would be to convert to route based VPNs. As you said, it's not possible to advertise a route which doesn't exist in your routing table. The other option is the proposed from you, to add static route pointing to your gateway through the proper outgoing interface for instance and then advertise it via OSPF.
I checked now the situation on another CP Gateway (r80.40) where we have other domain based VPNs and there I see the kernel Routes. BUT only the routes from the star communities.
Tried now to reconfigure my Mesh-Community to Star to check if the Routes will show up but no 😞
Those are not OS system level routes, those are VPN routes.
You can't redistribute that directly since routes in the vpn_routing table are not "real" routes that exist in the Gaia OS that OSPF can see.
If you are using at least R81, check out NAT Pools which should allow redistribution. Here is the relevant page from my Gaia 3.10 Immersion self-guided video series:
Cool! Thanks I can work with that handy solution!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
11 | |
7 | |
6 | |
6 | |
6 | |
5 | |
4 | |
4 | |
4 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY