Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gcarella
Participant
Jump to solution

Traffic to public peer it's always encrypted in VPN community tunnel

Hi all,

 

I would like to discuss with the community about a strange behavior that I'm experiencing on Check Point security gateway.

I state that I'm quite new with Check Point and I have less than 1yr of hands-on experience on this products. Therefore I often have doubts about topics or features that maybe are obvious to many.

Anyway what it's struggling me from some time is that when for example I launch a ping to a public peer of an active VPN community (star), the traffic is encrypted and sent over that tunnel instead to travel unencrypted towards internet interface.

For me this is a strange behavior I'm expecting that traffic shall go directly on internet as it happens on other VPN S2S implementation that I manage with other vendors.

The issue is present on Check Point SecGateway and CloudGuard, both with R80.30. 

 

Any idea why this happens?

 

Thanks,

1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

View solution in original post

4 Replies
PhoneBoy
Admin
Admin

The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut... 

gcarella
Participant

Thanks a lot.

There is a specific reason why the Secure Gateway includes public peers in the encryption domain?

PhoneBoy
Admin
Admin

No idea but it has been the default behavior pretty much since the product supported VPN.

the_rock
Legend
Legend

@PhoneBoy is 100% correct. Interfaces would be technically part of vpn domain by default, but if you follow the sk mentioned, you should be able to exclude them.

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events