> Source: [sk41970](https://support.checkpoint.com/results/sk/sk41970)

# sk41970 - SNMP Monitoring over VPN tunnel

| Property | Value |
|----------|-------|
| Solution ID | sk41970 |
| Date Created | 2009-06-01 |
| Last Modified | 2017-05-15 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * SNMP manager queries the status of the Internal interface of remote Firewall over VPN tunnel.
* ESP packet that comes from SNMP manager as encrypted, is decrypted by the Firewall and then being sent back, but the Firewall replies with the IP address of External interface as Source IP, and not with IP address of Internal interface, to which the SNMP query was sent to.
* The External interface of the Firewall is not inside the Encryption Domain, so Firewall doesn't encrypt the traffic and sends it in Clear with the Destination as internal IP address of the SNMP manager.

## Cause

Firewall replies with the closest interface to the Client and in this case, it is External interface

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
