---
title: Fun with routing VPNs on Checkpoint..
description: VPN Checkpoint routing
---

[Skip to content](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#main-content)

![thinking_sideways_final](https://thinking.net.nz/hs-fs/hubfs/thinking_sideways_final.png?width=4977&height=1883&name=thinking_sideways_final.png)

- [Products](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#products)
- [Services](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#services)
- [Blog](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#blog)
- [About](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#about)

Open main navigation

Close main navigation

- [Products](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#products)
- [Services](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#services)
- [Blog](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#blog)
- [About](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#about)
- [Contact us](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#contact)

[Contact us](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#contact)

 Oct 18, 2024 1:29:24 PM

# Fun with routing VPNs on Checkpoint..

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk)

Share: [facebook-f icon](http://www.facebook.com/share.php?u=https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint) [Twitter icon](https://twitter.com/intent/tweet?url=https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint) [pinterest-p icon](http://pinterest.com/pin/create/link/?url=https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint) [envelope icon](mailto:?body=https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint)

Some useful notes from the field

2 ways of providing routes to a Checkpoint VPN. Lets focus on Domain based for now;

- Domain Based VPN
- Route Based VPN

For Domain Based VPNs you define your gateways (external, interop, actual etc.).  In the course of this you set up interfaces and an encryption domain per interface. Lets say we have something like this, lets look at routing and how to manage it.

Destination Host <--> router(s) <--> GW1 <---> GW2 <--> Source Host

The problem is the destination host is X amount of hops away from GW1 and while its network may be in GW1 encryption domain routing will fly out the door of GW2 external interface via the default route as GW2 doesn't know where Destination Host1 is. Adding a static route to GW2 won't help as you cannot tie the route to VPN interface like you can if you had a Route Based VPN.

Options???

1. Convert to a Route Based VPN - fair enough
2. Use NAT - fair enough again
3. Use $FWDIR/conf/vpn\_route.conf on your management server to add a route to the VPN (this becomes a VPN route not a kernel route BTW

Check the Site to Site VPN Admin guide for syntax for your Checkpoint version.  Once done you will need to push policy to apply the change to your gateways.  Now all of this is well documented, for reference here are a few tools/commands to help with debug.

Debug - shows what happens to the packet

fw ctl zdebug drop | grep ip

Showing Encryption Domains on a  Gateway - Paste this lot into the CLI

if \[\[ \`$CPDIR/bin/cpprod\_util FwIsFirewallModule 2>/dev/null\` != \*'1'\* \]\];then echo;tput bold;tput setab 1;echo ' Not a firewall gateway! ';tput sgr0;echo;else if \[\[ \`grep R80.40 /etc/cp-release|wc -l\` != 0 \]\];then echo;tput bold;tput setab 1;echo -n ' Info: VPN Domain for Gateway Communities are currently not displayed correctly by this tool! ';tput sgr0;echo;fi;fw tab -t vpn\_routing -u|awk 'NR>3 {$0=substr($0,2,28);gsub(", ", "");gsub("; ", "");gsub("..", "0x& "); print}'|xargs printf "%d.%d.%d.%d %d.%d.%d.%d %d.%d.%d.%d\\n"|awk '{print $3"."$1" - "$2}'|sort -t . -k  1,1n -k 2,2n -k 3,3n -k 4,4n -k 5,5n -k 6,6n -k 7,7n -k 8,8n|sed 's/^/x/'|sed 's/\\./\\n\\t/4'|awk '!x\[$0\]++'|sed '/x/s/$/\\n\\tEncryption domain/'|sed 's/x/\\nVPN Gateway > /'|if \[\[ $(cat /etc/cp-release) != \*"Embedded"\* \]\];then egrep -C 9999 --color=auto $'VPN Gateway|Encryption domain';else cat $1|sed 's/^\\t//';fi;echo;fi;if \[\[ \`grep R80.40 /etc/cp-release|wc -l\` != 0 \]\];then tput bold;tput setab 1;echo -n ' Info: VPN Domain for Gateway Communities are currently not displayed correctly by this tool! ';tput sgr0;echo;echo;fi

Example Output showing topology

VPN Gateway > 100.100.2.155  
Encryption domain  
100.100.2.155 - 100.100.2.155  
103.23.143.142 - 103.23.143.142  
172.16.3.98 - 172.16.3.98  
172.18.16.0 - 172.18.16.31  
172.18.16.33 - 172.18.16.33  
172.18.16.64 - 172.18.16.95

VPN Gateway > 103.252.247.33  
Encryption domain  
10.16.1.0 - 10.16.1.255  
10.16.255.0 - 10.16.255.255  
10.20.3.215 - 10.20.3.215  
....

Showing VPN Routes on a Gateway - not supported on embedded GAAI gateways

fw tab -f -t vpn\_routing -u

Bit ugly so try this from [Heiko Ankenbrand](https://community.checkpoint.com/migrated-users/55229)

echo -e "\\033\[0m####################\\n# VPN Routing      #\\n####################";fw tab -f -t vpn\_routing -u 2>&1 |grep -v "+"| awk '{split($0,a,";"); print a\[8\]}' |sort -n |uniq | awk '{split($0,a," "); print a\[2\]}' | xargs -I % sh -c  'echo -n "External Gateway: ";echo -e "\\033\[0;31m % \\\\033\[37m";echo -e "  Routing: \\033\[32m";fw tab -f -t vpn\_routing -u 2>&1 |grep % |awk '\\''{split($0,b,";"); print b\[6\] b\[7\]}'\\''| sed 's/From\\://'| sed 's/To\\:/-/'|sort -u ;echo -e "\\033\[0m" '

Looks like this

![vpn-route](https://thinking.net.nz/hs-fs/hubfs/vpn-route.jpg?width=998&height=553&name=vpn-route.jpg)

 

 

[Checkpoint](https://thinking.net.nz/blog/tag/checkpoint)

## Related posts

## [Managing Digital Certs and CSR in RSA Authentication Manager](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Sep 3, 2024 1:31:10 PM

How to clean up CSR's You have created one or more CSR (certificate signing requests), not all can...

[Read more](https://thinking.net.nz/blog/managing-digital-certs-and-csr-in-rsa-authentication-manager)

[RSA](https://thinking.net.nz/blog/tag/rsa)

## [Linux 2FA using PAM and RSA](https://thinking.net.nz/blog/linux-2fa-using-pam-and-rsa)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Sep 2, 2024 1:33:57 PM

When you look down the list of supported Linux distributions officially supported by RSA there are...

[Read more](https://thinking.net.nz/blog/linux-2fa-using-pam-and-rsa)

## [How to Detect MS17-010 Vulnerability in Your Systems](https://thinking.net.nz/blog/how-to-detect-ms17-010-vulnerability-in-your-systems)

![Picture of JK](https://app.hubspot.com/settings/avatar/d07d287c41a806c015d4f2548c90ba4f) [JK](https://thinking.net.nz/blog/author/jk) 

 Sep 3, 2024 1:25:16 PM

Uncover the critical steps to identify and mitigate the infamous MS17-010 vulnerability that...

[Read more](https://thinking.net.nz/blog/how-to-detect-ms17-010-vulnerability-in-your-systems)

[Follow us on Linkedin](https://www.linkedin.com/company/thinking2014limited) [Thinking Service Portal](https://thinking.myportallogin.com.au/) [Download our Terms of Business](https://thinking.net.nz/terms-of-business)

- [Products](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#products)
- [Services](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#services)
- [Blog](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#blog)
- [About](https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint#about)

---

[![thinking_sideways_final](https://thinking.net.nz/hs-fs/hubfs/thinking_sideways_final.png?width=4977&height=1883&name=thinking_sideways_final.png "thinking_sideways_final")](https://www.thinking.net.nz)

Postal: PO Box 26, Waimauku, Auckland 0842, New Zealand

Email:enquires@thinking.net.nz

Copyright © 2024

Thinking (2014) Limited

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "JK",
    "url" : "https://thinking.net.nz/blog/author/jk"
  },
  "dateModified" : "2024-10-22T21:08:55.849Z",
  "datePublished" : "2024-10-18T00:29:24.000Z",
  "headline" : "Fun with routing VPNs on Checkpoint..",
  "mainEntityOfPage" : {
    "@id" : "https://thinking.net.nz/blog/fun-with-vpns-on-checkpoint",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Thinking (2014) Limited"
  }
}
```