> Source: [sk185140](https://support.checkpoint.com/results/sk/sk185140)

# sk185140 - Maestro SGMs cannot communicate via SSH/SCP when VPN community member is configured with the All_Internet encryption domain

| Property | Value |
|----------|-------|
| Solution ID | sk185140 |
| Date Created | 2026-07-09 |
| Last Modified | 2026-07-15 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R82.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Security Group Members pass data plane traffic successfully.

* Remote CLI access between Security Group Members (SGMs) fails (gClish -- Gaia command shell).

* SSH or SCP between SGMs fails.

* Issue occurs when the Security Group is part of a Site-to-Site VPN community with one of the VPN community members is configured with an encryption domain of:  
  `All_Internet object (0.0.0.1 - 255.255.255.255)`

## Cause

A VPN community member is configured with the **All_Internet** encryption domain and uses the **Encrypt** action.  
This configuration causes the effective encryption domain to include all IP ranges.  

As a result, internal Maestro networks are also included:

* CIN (Cluster Internal Network) - used for internal cluster communication.
* SYNC network - used for state synchronization between Security Group Members.

Traffic between SGMs matches the VPN encryption domain. The system sends this traffic to the IPsec tunnel instead of keeping it inside the Maestro infrastructure. This behavior blocks internal management protocols such as SSH, SCP, and gClish.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
