- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Traffic to public peer it's always encrypted i...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Traffic to public peer it's always encrypted in VPN community tunnel
Hi all,
I would like to discuss with the community about a strange behavior that I'm experiencing on Check Point security gateway.
I state that I'm quite new with Check Point and I have less than 1yr of hands-on experience on this products. Therefore I often have doubts about topics or features that maybe are obvious to many.
Anyway what it's struggling me from some time is that when for example I launch a ping to a public peer of an active VPN community (star), the traffic is encrypted and sent over that tunnel instead to travel unencrypted towards internet interface.
For me this is a strange behavior I'm expecting that traffic shall go directly on internet as it happens on other VPN S2S implementation that I manage with other vendors.
The issue is present on Check Point SecGateway and CloudGuard, both with R80.30.
Any idea why this happens?
Thanks,
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The gateway interfaces are always included in the encryption domain, even if you don't explicitly include them.
To exclude a given IP from encryption: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks a lot.
There is a specific reason why the Secure Gateway includes public peers in the encryption domain?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No idea but it has been the default behavior pretty much since the product supported VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhoneBoy is 100% correct. Interfaces would be technically part of vpn domain by default, but if you follow the sk mentioned, you should be able to exclude them.
Andy
