Locally managed SMBs .def files for VPN fine-tunin... - Check Point CheckMates

Locally managed SMBs .def files for VPN fine-tuning

This is a follow-up to SMB units SMS files for VPN fine-tuning after reading Yuri Slobodyanyuk's blog on IT Security and Networking. He speaks of changes to .def files like crypt.def for VPN Fine-Tuning that are usually made on the SMS and installed on a GW by a policy install. SMB units also have these files - crypt.def can be found in /pfrm2.0/config1/fw1/lib/ or /pfrm2.0/config2/fw1/lib/ and in /opt/fw1/lib/crypt.def.

The VPN configuration from sk108600 VPN Site-to-Site with 3rd party and sk86582 Excluding subnets in encryption domain from accessing a specific VPN community can also be found on locally managed SMBs crypt.def and edited there. As locally managed SMB units have no manual policy install command to recompile and apply these changes, Yuri points out that reboot would activate the new settings, but also, a much easier way is available ("not listed in any Checkpoint documentation", but you can find it in sk97949, sk100278 and sk108274), changes can be applied by issuing:

[Expert]# fw_configload

The sk100278 gives two commands to apply changes from an edited $FWDIR/conf/trac_client_1.ttm file:

[Expert]# fw_configload

[Expert]# sfwd_restart

So i have asked R&D for more information and i have received the following as the officially supported procedures: In locally managed SMB appliances it’s possible to edit /opt/fw1/lib/crypt.def, but user.def is not officially supported. Also note that sk30919 does not list SMB as relevant Product. Only crypt.def can be modified, and afterwards ‘ vpn_configload’ is good enough for the change to take effect.

Supported for locally managed SMB appliances are changes to crypt.def to enable VPN features not available in WebGUI or CLI. We learn that the files from /pfrm2.0/config1/ or /pfrm2.0/config2/ are linked to /opt/fw1/lib/. And we learn the command vpn_configload !

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

6\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

8 Replies

Pedro_Espindola

Employee

‎2019-12-2603:37 PM

Show option menu

Gunther, do you know how to make the procedure from "sk114882 - Remote Access clients configuration based on group membership" work on SMB gateways?

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2019-12-2608:30 PM

Show option menu

In response to Pedro_Espindola

Actually there seems to be a shell script on SMB that appears to do the vpn_configload thingy the right way:

/opt/fw1/bin/vpn_configload.sh

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2020-01-0901:16 AM

Show option menu

In response to HristoGrigorov

That is just the command i have mentioned far above 8)

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

HristoGrigorov

MVP Gold

‎2020-01-1009:03 PM

Show option menu

In response to G_W_Albrecht

vpn_configload is binary and vpn_configload.sh is shell script.... so actually there are two commands.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2020-01-0901:15 AM

Show option menu

You could try with a User group defined in Users & Objects > Users Management > Users

and

/pfrm2.0/opt/fw1/conf/trac_client_1.ttm

/pfrm2.0/config2/fw1/conf/trac_client_1.ttm

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Baasanjargal_Ts

Advisor

‎2020-08-0205:59 PM

Show option menu

In response to G_W_Albrecht

Hello

I am trying to configure universal tunnel on Check Point SMB firewall with 3rd party. Branch router has  0.0.0.0 0.0.0.0 subnet for the tunnel destination side. Check Point SMB firewall is enabled Allow remote gateway all traffic pass through this gateway option.

Problem is: Branch hosts access to internet through their own router instead of check point SMB.

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

G_W_Albrecht

MVP Silver

‎2020-08-1901:47 AM

Show option menu

In response to Baasanjargal_Ts

The SMB Route all traffic thru GW option is for RA clients only, not for IPSEc VPN tunnels. So the branch router is having an issue when not routing everything into the VPN...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

ereche

Participant

‎2025-04-1003:28 PM

Show option menu

I'm looking for a solution, trying to solve the mystery of why even if i put is on SMS crypt.def it's not work. Now i know, SMB is everything different and there`s no documentation about it. We do these steps on Quantum Spark 1900 and solve the problem.

Do this on SMS, not on GW. Depends on version SMS you have to choose correct file.

vi /opt/CPSFWR81CMP-R82/lib/crypt.def

Insert these lines on the file and save it.

define USERC_CHECK(rule) {

( in userc_rules)

};

#ifndef NON_VPN_TRAFFIC_RULES

#ifndef IPV6_FLAVOR

#define NON_VPN_TRAFFIC_RULES (dst=192.168.5.1 or dst=192.168.5.2)

#else

#define NON_VPN_TRAFFIC_RULES 0

#endif

#endif

#endif /* __crypt_def__ */

Then install policy on gateways and see the logs. The traffic will pass directly do p2p and not encrypted anymore.

2.png

Preview file

58 KB

1.png

Preview file

30 KB

2\ \ \ Kudos

Click here to give kudos to this post.

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

Reply

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

User Count

sx8n20394
7

israelfds95
7

jorgeluiznim
5

velo
1

BikeMan
1

emmap
1

CEEJAY
1

Max_Leorne
1

Chris_Atkinson
1

View All ≫

Trending Discussions

Reach My Device – A Native Option for Secure Remote Access to Quantum Spark Appliances

Downgrading a Quantum Spark Appliance: From 'Upgrade Not Supported' to a Working Boot Loader Recover

L2TP Remote Access VPN - Can't Connect on SMB 2550 R82.00.10

Upcoming Events

Sort by:

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Thu 30 Jul 2026 @ 11:30 AM (CDT)

CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On

Virtual

Tue 28 Jul 2026 @ 11:00 AM (EDT)

Virtual

Wed 29 Jul 2026 @ 12:00 PM (SGT)

Virtual

Wed 29 Jul 2026 @ 02:00 PM (IDT)

Virtual

Wed 29 Jul 2026 @ 03:00 PM (CEST)

Virtual

Wed 29 Jul 2026 @ 11:00 AM (EDT)

TechTalk: On-Premise SD-WAN Management

Virtual

Thu 30 Jul 2026 @ 10:00 AM (PDT)

AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway

In-Person

Tue 11 Aug 2026 @ 11:30 AM (EDT)

New York City: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 13 Aug 2026 @ 11:30 AM (EDT)

Waltham, MA: Agentic AI Security Deep Dive & Hands-On

In-Person

Thu 20 Aug 2026 @ 08:30 AM (COT)

Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA

In-Person

Thu 20 Aug 2026 @ 06:00 PM (COT)

Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad

In-Person

Thu 27 Aug 2026 @ 09:00 AM (CEST)

Check Point Hands-On SASE and Cloud Workshop - Zurich

In-Person

Wed 21 Oct 2026 @ 09:00 AM (BST)

AI Security Workshop - Glasgow

CheckMates Events

Top

About CheckMates

Learn Check Point

Advanced Learning

Resources

Non-English Discussions

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us CheckMates on LinkedIn Check Point on YouTube CheckMates on Facebook CheckMates on Instagram

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. Copyright Privacy Policy About Us UserCenter

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.