- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
No Attack Required
Hello,
I have a customer with several locally managed SMB gateways. Each SMB gateway has at least 03 VPN DOMAIN. The need arose to configure some VTI VPN. In the documentation, VTI VPN requires that the tunnel is per gateway pair. In the SMB gateway settings I only find this setting globally. I cannot change this configuration globally, because VPN DOMAIN will be unavailable. I need to find a way to configure VPN DOMAIN and VPN VTI on the SMB gateway, without changing this configuration globally.
Let me spin up quick smb spark demo and see.
Andy
Hey, not sure what was the setting you were referring to, but is it possible its below?
Andy
Hello the_rock.
The configuration I'm referring to is the one below.
One of the requirements for configuring VTI is that we use gateway pair configuration.
My apologies, I cant seem to find that in demo I spun up, but will check again. So you are saying thats global option?
Andy
Yes, it is a global configuration.
I need to find a way to do this configuration on each VPN site. Some VPNs will have a subnet pair and others will have a gateway pair.
So sorry I dont have access to real smb device to test : - (. Is there any setting on specific vpn tunnel that would let you change it or this is the only place?
Andy
This is exactly what I'm looking for. It seems to me that there is only this global configuration.
Got it. Are you allowed to do remote? I really want to try and help with this, because I have a gut feeling might be possible.
Andy
Unfortunately, our internal policy does not allow this.
Understood. So, if you edit any given vpn tunnel, you dont see option to change this individually at all?
Andy
Correct, I don't see any option to change this individually.
If this option exists, it must be within some configuration file in the shell.
Maybe SMB master @G_W_Albrecht might know? Otherwise, I would recommend asking TAC via official case. I will keep checking in the meantime, just bit tricky with demo, as I cant seem to get RDP to open in full screen.
Andy
I just created bogus tunnel and sadly, cant see option anywhere in the settings similar to below in smart console community.
Andy
The checkpoint instructed me to configure the unnumbered VTI.
Thats fine, but not sure if that really addresses your issue specifically?
Andy
Though, now that I read that sk again @Marquevis , appears it should help, since its related to individual vpn tunnel.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 7 | |
| 3 | |
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 11 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IATue 11 Aug 2026 @ 11:00 AM (EDT)
Beyond Phishing: Securing Email Against SaaS and AI-Driven ThreatsThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY