<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with CloudGuard remote access VPN on Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152010#M1046</link>
    <description>&lt;P&gt;the outgoing is ok.&lt;/P&gt;
&lt;P&gt;under the IPSEC VPN in the GW properties there's VPN LINK SELECTION.&lt;/P&gt;
&lt;P&gt;what did you choose there ?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jun 2022 11:51:59 GMT</pubDate>
    <dc:creator>Nir_Shamir</dc:creator>
    <dc:date>2022-06-29T11:51:59Z</dc:date>
    <item>
      <title>Solved: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151951#M1039</link>
      <description>&lt;P&gt;I have a CloudGuard HA and management and my problem is remote access VPN is disconnecting roughly every 30 seconds. In the logs I can see "According to the policy the packet should not have been decrypted" is the reason tunnel test is being dropped.&lt;/P&gt;&lt;P&gt;Setup&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Frontend subnet has NSG allowing all inbound and outbound traffic&lt;/LI&gt;&lt;LI&gt;image is R81.10&lt;/LI&gt;&lt;LI&gt;frontend eth0 leads to "external"&lt;/LI&gt;&lt;LI&gt;backend eth1 leads to "this network"&lt;/LI&gt;&lt;LI&gt;office mode configured (10.255.255.0/24)&lt;/LI&gt;&lt;LI&gt;remote access vpn domain does not contain office mode range&lt;/LI&gt;&lt;LI&gt;anti-spoofing is off on both eth0 and eth1&lt;/LI&gt;&lt;LI&gt;vpn link selection is statically NAT'd IP: public cluster VIP&lt;/LI&gt;&lt;LI&gt;outgoing VPN link is private cluster VIP&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Things I tried:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Adding NAT rule as in sk106853 to translate tunnel test traffic to the public VIP to LocalGatewayExternal&lt;/LI&gt;&lt;LI&gt;Adding policy rule as in sk44075 to accept tunnel test mapped to LocalGatewayExternal&lt;/LI&gt;&lt;LI&gt;Modified (2) to also accept tunnel test to the public VIP&lt;/LI&gt;&lt;LI&gt;Turned on anti-spoofing for office mode as in sk44075. Anti-spoofing for eth0 and eth1 still off&lt;/LI&gt;&lt;LI&gt;Verified "accept control connections" and "accept remote access control connections" are checked&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;Solved:&lt;/STRONG&gt; &lt;SPAN&gt;&amp;nbsp;The public VIP has to be added to the remote access encryption domain. The other stuff in the "Things I tried" section are not needed except to make sure the implied rules in (5) are selected.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 03:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151951#M1039</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-06-30T03:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151952#M1040</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/62540"&gt;@RickyDan&lt;/a&gt; i think the issue could be using the office mode configured (10.255.255.0/24). Try using another subnet&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2022 21:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151952#M1040</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2022-06-28T21:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151962#M1041</link>
      <description>&lt;P&gt;Changed it to 10.10.10.0/24 and it did not work.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 01:19:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151962#M1041</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-06-29T01:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151996#M1042</link>
      <description>&lt;P&gt;what did you choose under "VPN Link Selection" ?&lt;/P&gt;
&lt;P&gt;it should be "NATTED IP" with the Public IP of your CLUSTER VIP.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 09:45:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/151996#M1042</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-06-29T09:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152002#M1043</link>
      <description>&lt;P&gt;hi, yes that is how it is configured. forgot to put that in the post. the outgoing link is set as the private VIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 10:56:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152002#M1043</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-06-29T10:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152003#M1044</link>
      <description>&lt;P&gt;it need to be the Public VIP , not the private VIP.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 11:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152003#M1044</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-06-29T11:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152008#M1045</link>
      <description>&lt;P&gt;hi, these are the current config for outgoing route selection. what do you recommend?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;outgoing route selection:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="out-1.PNG" style="width: 398px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17068i92D7FF94FCA1A9D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="out-1.PNG" alt="out-1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;setup:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="out-2.PNG" style="width: 326px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17069i2008CB969E53812E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="out-2.PNG" alt="out-2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;source ip address setting:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="out-3.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17070i2EB1AC10DA6E933D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="out-3.PNG" alt="out-3.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 11:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152008#M1045</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-06-29T11:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152010#M1046</link>
      <description>&lt;P&gt;the outgoing is ok.&lt;/P&gt;
&lt;P&gt;under the IPSEC VPN in the GW properties there's VPN LINK SELECTION.&lt;/P&gt;
&lt;P&gt;what did you choose there ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 11:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152010#M1046</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2022-06-29T11:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with CloudGuard remote access VPN on Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152015#M1047</link>
      <description>&lt;P&gt;that is set to statically NAT'd IP: public cluster VIP&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 12:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Solved-Need-help-with-CloudGuard-remote-access-VPN-on-Azure/m-p/152015#M1047</guid>
      <dc:creator>RickyDan</dc:creator>
      <dc:date>2022-06-29T12:35:27Z</dc:date>
    </item>
  </channel>
</rss>

