## Locally managed SMBs .def files for VPN fine-tuning

This is a follow-up to [_SMB units SMS files for VPN fine-tuning_](https://community.checkpoint.com/docs/DOC-2746-smb-units-sms-files-for-vpn-fine-tuning) after reading [Yuri Slobodyanyuk](https://community.checkpoint.com/people/nvyur286c2b4b-2416-37b0-91f3-c73611b3277a)'s blog on IT Security and Networking. He speaks of changes to _.def_ files like _crypt.def_ for VPN Fine-Tuning that are usually made on the SMS and installed on a GW by a policy install. SMB units also have these files - _crypt.def_ can be found in _/pfrm2.0/config1/fw1/lib/_ or _/pfrm2.0/config2/fw1/lib/_ and in _/opt/fw1/lib/crypt.def_.

The VPN configuration from _[sk108600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600&partition=Advanced&product=IPSec) [VPN Site-to-Site with 3rd party](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600&partition=Advanced&product=IPSec)_ and _[sk86582 Excluding subnets in encryption domain from accessing a specific VPN community](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86582&partition=Advanced&product=IPSec)_ can also be found on locally managed SMBs _crypt.def_ and edited there. As locally managed SMB units have no manual policy install command to recompile and apply these changes, Yuri points out that reboot would activate the new settings, but also, a much easier way is available ("not listed in any Checkpoint documentation", but you can find it in _sk97949_, _sk100278_ and _sk108274_), changes can be applied by issuing:

_\[Expert\]# fw\_configload_

The _sk100278_ gives two commands to apply changes from an edited _$FWDIR/conf/trac\_client\_1.ttm_ file:

_\[Expert\]# fw\_configload_

_\[Expert\]# sfwd\_restart_

So i have asked R&D for more information and i have received the following as the officially supported procedures: In locally managed SMB appliances it’s possible to edit _/opt/fw1/lib/crypt.def_, but _user.def_ is not officially supported. Also note that _sk30919_ does not list SMB as relevant Product. Only _crypt.def_ can be modified, and afterwards ‘ _vpn\_configload_’ is good enough for the change to take effect.

Supported for locally managed SMB appliances are changes to _crypt.def_ to enable VPN features not available in WebGUI or CLI. We learn that the files from _/pfrm2.0/config1/_ or _/pfrm2.0/config2/_ are linked to _/opt/fw1/lib/._ And we learn the command _vpn\_configload !_

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

- Tags:
- [smb](https://community.checkpoint.com/t5/tag/smb/tg-p/board-id/smb-smp)

- [smb configuration](https://community.checkpoint.com/t5/tag/smb%20configuration/tg-p/board-id/smb-smp)

[6\\
\\
\\
Kudos](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1618/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/39640?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

- [All forum topics](https://community.checkpoint.com/t5/Spark-Firewall-SMB/bd-p/smb-smp/page/22 "Spark Firewall (SMB)")
- [Previous Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/td-p/228367 "Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade")
- [Next Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Cluster-of-two-SMB-1900/td-p/246187 "Cluster of two SMB 1900")

8 Replies

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2019-12-2603:37 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=2765)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71239/highlight/true#M2765)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/2765/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/71239)

Gunther, do you know how to make the procedure from "[sk114882 - Remote Access clients configuration based on group membership](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114882 "sk114882 - Remote Access clients configuration based on group membership")" work on SMB gateways?

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/71239?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2019-12-2608:30 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=2766)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71241/highlight/true#M2766)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/2766/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/71241)

[In response to Pedro\_Espindola](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71239/highlight/true#M2765)

Actually there seems to be a shell script on SMB that appears to do the vpn\_configload thingy the right way:

/opt/fw1/bin/vpn\_configload.sh

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/71241?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2020-01-0901:16 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=2813)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71913/highlight/true#M2813)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/2813/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/71913)

[In response to HristoGrigorov](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71241/highlight/true#M2766)

That is just the command i have mentioned far above 8)

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/71913?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2020-01-1009:03 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=2820)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/72091/highlight/true#M2820)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/2820/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/72091)

[In response to G\_W\_Albrecht](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71913/highlight/true#M2813)

vpn\_configload is binary and vpn\_configload.sh is shell script.... so actually there are two commands.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/72091?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2020-01-0901:15 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=2812)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71912/highlight/true#M2812)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/2812/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/71912)

You could try with a User group defined in Users & Objects > Users Management > Users

and

/pfrm2.0/opt/fw1/conf/trac\_client\_1.ttm

/pfrm2.0/config2/fw1/conf/trac\_client\_1.ttm

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/71912?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[Baasanjargal\_Ts](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1091)

Advisor

‎2020-08-0205:59 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=3948)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/93109/highlight/true#M3948)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/3948/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/93109)

[In response to G\_W\_Albrecht](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/71912/highlight/true#M2812)

Hello

I am trying to configure universal tunnel on Check Point SMB firewall with 3rd party. Branch router has  0.0.0.0 0.0.0.0 subnet for the tunnel destination side. Check Point SMB firewall is enabled Allow remote gateway all traffic pass through this gateway option.

Problem is: Branch hosts access to internet through their own router instead of check point SMB.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/93109?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2020-08-1901:47 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=4058)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/94573/highlight/true#M4058)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/4058/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/94573)

[In response to Baasanjargal\_Ts](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/93109/highlight/true#M3948)

The SMB Route all traffic thru GW option is for RA clients only, not for IPSEc VPN tunnels. So the branch router is having an issue when not routing everything into the VPN...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/94573?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

[ereche](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63594)

Participant

‎2025-04-1003:28 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=12452)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/m-p/246217/highlight/true#M12452)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/12452/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/246217)

I'm looking for a solution, trying to solve the mystery of why even if i put is on SMS crypt.def it's not work. Now i know, SMB is everything different and there\`s no documentation about it. We do these steps on Quantum Spark 1900 and solve the problem.

Do this on SMS, not on GW. Depends on version SMS you have to choose correct file.

vi /opt/CPSFWR81CMP-R82/lib/crypt.def

Insert these lines on the file and save it.

define USERC\_CHECK(rule) {

(<src> in userc\_rules)

};

#ifndef NON\_VPN\_TRAFFIC\_RULES

#ifndef IPV6\_FLAVOR

#define NON\_VPN\_TRAFFIC\_RULES (dst=192.168.5.1 or dst=192.168.5.2)

#else

#define NON\_VPN\_TRAFFIC\_RULES 0

#endif

#endif

#endif /\* \_\_crypt\_def\_\_ \*/

Then install policy on gateways and see the logs. The traffic will pass directly do p2p and not encrypted anymore.

- Tags:
- [crypt.def](https://community.checkpoint.com/t5/tag/crypt.def/tg-p/board-id/smb-smp)

[2.png](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640?attachment-id=12888)

Preview file

58 KB

[1.png](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640?attachment-id=12889)

Preview file

30 KB

[2\\
\\
\\
Kudos](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/12452/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/246217?t:ac=board-id/smb-smp/thread-id/1618&t:cp=kudos/contributions/tapletcontributionspage&ticket=pyloDjNiP49u_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

| User | Count |
| --- | --- |
| <br>[sx8n20394](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107449) | 7 |
| <br>[israelfds95](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117) | 7 |
| <br>[jorgeluiznim](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85528) | 5 |
| <br>[velo](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110726) | 1 |
| <br>[BikeMan](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54723) | 1 |
| <br>[emmap](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054) | 1 |
| <br>[CEEJAY](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/112446) | 1 |
| <br>[Max\_Leorne](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/142185) | 1 |
| <br>[Chris\_Atkinson](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630) | 1 |

[View All ≫](https://community.checkpoint.com/t5/forums/kudosleaderboardpage/board-id/smb-smp/timerange/one_month/page/1/tab/authors)

Trending Discussions

[Reach My Device – A Native Option for Secure Remote Access to Quantum Spark Appliances](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reach-My-Device-A-Native-Option-for-Secure-Remote-Access-to/td-p/280076)

[Downgrading a Quantum Spark Appliance: From 'Upgrade Not Supported' to a Working Boot Loader Recover](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Downgrading-a-Quantum-Spark-Appliance-From-Upgrade-Not-Supported/td-p/279888)

[L2TP Remote Access VPN - Can't Connect on SMB 2550 R82.00.10](https://community.checkpoint.com/t5/Spark-Firewall-SMB/L2TP-Remote-Access-VPN-Can-t-Connect-on-SMB-2550-R82-00-10/td-p/279943)

Upcoming Events

Sort by:

- [All](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640#)
- [Virtual](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640#)
- [In-Person](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640#)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats](https://community.checkpoint.com/t5/CheckMates-Events/Under-the-Hood-Check-Point-and-Illumio-Modern-Network-Defense/ev-p/279701)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280019)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280021)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280020)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

Thu 30 Jul 2026 @ 11:30 AM (CDT)

[CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/CheckMates-Live-DFW-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279920)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Thu 30 Jul 2026 @ 10:00 AM (PDT)

[AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Masters-E12-READY-OR-NOT-Securing-the-AI-Enterprise/ev-p/277411)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Tue 11 Aug 2026 @ 11:30 AM (EDT)

[New York City: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/New-York-City-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279476)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 13 Aug 2026 @ 11:30 AM (EDT)

[Waltham, MA: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/Waltham-MA-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279475)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 08:30 AM (COT)

[Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Evolution-Hybrid-Mesh-Management-Visibilidad/ev-p/280003)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 06:00 PM (COT)

[Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Intelligence-IA-Generativa-en-Acci%C3%B3n-para/ev-p/280004)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 27 Aug 2026 @ 09:00 AM (CEST)

[Check Point Hands-On SASE and Cloud Workshop - Zurich](https://community.checkpoint.com/t5/CheckMates-Events/Check-Point-Hands-On-SASE-and-Cloud-Workshop-Zurich/ev-p/279914)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Wed 21 Oct 2026 @ 09:00 AM (BST)

[AI Security Workshop - Glasgow](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Workshop-Glasgow/ev-p/278505)

[CheckMates Events](https://community.checkpoint.com/t5/CheckMates-Events/eb-p/events)

[Top](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Locally-managed-SMBs-def-files-for-VPN-fine-tuning/td-p/39640)

About CheckMates

- [Getting Started & FAQ](https://community.checkpoint.com/t5/help/faqpage)
- [Community Guidelines](https://community.checkpoint.com/t5/user/TermsOfServicePage)

Learn Check Point

- [Check Point for Beginners](https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/bg-p/check-point-for-beginners-2-0)
- [Check Point Trivia](https://community.checkpoint.com/t5/Check-Point-Trivia/bg-p/trivia)
- [CheckFlix Videos](https://community.checkpoint.com/t5/CheckFlix/ct-p/checkflix)

Advanced Learning

- [Check Point Security Masters](https://community.checkpoint.com/t5/Check-Point-Security-Masters/gp-p/ccsm)
- [Tip of the Week](https://community.checkpoint.com/t5/SecureKnowledge-Tip-of-the-Week/bg-p/secureknowledge)
- [TechTalks](https://community.checkpoint.com/t5/TechTalks/ct-p/techtalks%20role=)
- [Training and Certification](https://community.checkpoint.com/t5/Training-and-Certification/bd-p/training-and-certification)

Resources

- [CheckMates Toolbox](https://community.checkpoint.com/t5/CheckMates-Toolbox/ct-p/CheckMatesToolbox)
- [Developers (Code Hub)](https://community.checkpoint.com/t5/Developers-API-CLI/bd-p/codehub)
- [Product Announcements](https://community.checkpoint.com/t5/Product-Announcements/bg-p/products-blog)
- [Upcoming Events](https://community.checkpoint.com/t5/Upcoming-Events/bg-p/checkmates-live)

Non-English Discussions

- [Español](https://community.checkpoint.com/t5/Espa%C3%B1ol/bd-p/spanish)
- [French](https://community.checkpoint.com/t5/Fran%C3%A7ais/bd-p/francais)
- [Japanese](https://community.checkpoint.com/t5/Japanese-%E6%97%A5%E6%9C%AC%E8%AA%9E/bd-p/Japanese)
- [Português](https://community.checkpoint.com/t5/Portugu%C3%AAs/bd-p/portuguese)
- [Russian](https://community.checkpoint.com/t5/Russian/bd-p/russian)
- [Chinese](https://community.checkpoint.com/t5/Chinese/bd-p/taiwan)

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us [CheckMates on LinkedIn](http://linkedin.com/company/cpcheckmates)  [Check Point on YouTube](https://www.youtube.com/user/CPGlobal) [CheckMates on Facebook](https://www.facebook.com/cpcheckmates/) [CheckMates on Instagram](https://www.instagram.com/cpcheckmates/)

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. [Copyright](https://www.checkpoint.com/copyright/) [Privacy Policy](https://www.checkpoint.com/privacy/) [About Us](https://www.checkpoint.com/about-us/) [UserCenter](https://usercenter.checkpoint.com/)

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
