- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I have a couple of SMB 1500 devices setup for various home users. We set these devices up with the ability to sit on their private network at home so the appliance is setup as a DAIP gateway with a private DHCP address from their home network on the WAN interface of the SMB (did this to make it easy on the end use so they can just plug in the device at home and flexibility to move the device around).
Once they get plugged in, IPSEC VPN is configured and it will create a tunnel to the main site and have connectivity.
One limitation I found on the appliance itself - I'd like to send services such as DNS, NTP, ICMP from the appliance itself down the tunnel using the LAN IP of the appliance instead of the WAN IP. Currently, those requests are trying to be sent down the tunnel using the WAN IP which could be any private IP on the home user's network. I don't want to define the user's home networks as part of the encryption domain so if there is some kind of workaround to use the SMB's LAN IP to send those requests, that'd be great. Any ideas on this?
Centrally Managed Solution:
Firmware R77.20.80 and higher (SMB-4577) adds the same functionality for Centrally Managed Devices.
In order to enable the feature a kernel parameter should be used - fw ctl set int fw_enc_conns_use_internal 1
In Advanced Settings search for "source" and you should find applicable options to assist i.e.
"Use internal IP address for encrypted connections from local gateway"
Is there something similar for the 1430s? Searching for similar terms in Advanced Settings is telling me no.
CaseyB - See my reply to Chris above. Mine is centrally managed...may be a difference between centrally and locally managed gateways...
Forgot to mention - this is a centrally managed gateway. Per https://community.checkpoint.com/t5/SMB-Gateways-Spark/R80-20-15-Locally-Managed-Advanced-Settings/t... it looks like "VPN Site to Site global settings - Use internal IP address for encrypted connections from local gateway" is a valid option for locally managed SMBs. Hoping there may be something in GUIDBEdit for centrally managed...
Centrally Managed Solution:
Firmware R77.20.80 and higher (SMB-4577) adds the same functionality for Centrally Managed Devices.
In order to enable the feature a kernel parameter should be used - fw ctl set int fw_enc_conns_use_internal 1
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY