<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure encryption domain to allow specific users access from a different subnet in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104102#M10132</link>
    <description>&lt;P&gt;Behind the 5100, we have :&lt;/P&gt;&lt;P&gt;192.168.0.1/23&amp;nbsp; - office network, wifi, domain controllers, etc.&lt;/P&gt;&lt;P&gt;172.16.3.0/24 - Encryption domain for site to site VPNs&lt;/P&gt;&lt;P&gt;10.x.x.x - Engineering servers&lt;/P&gt;&lt;P&gt;Right now the way users access the encryption domain is by connecting to a local RRAS server which authenticates their account and gives them an IP on the 172.16.3.0/24 network (locally or remotely).&amp;nbsp; This then allows them to have access through some or all of the site to site VPN's using that encryption domain.&amp;nbsp; This is messy and we would like to get rid pf the RRAS server.&amp;nbsp; I know there is a lot going on here and I think it is more about improper network design, etc.&amp;nbsp; However, I was thinking there must be a way using our Checkpoint gateway to allow some users in 192.168.0.1/23 to use an IP in the 172.16.0.0/24 network.&amp;nbsp; You might be right about fixed IP's and NAT rules but that is a lot of work for me!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 08:23:08 GMT</pubDate>
    <dc:creator>Daniel_Bourne</dc:creator>
    <dc:date>2020-12-03T08:23:08Z</dc:date>
    <item>
      <title>Configure encryption domain to allow specific users access from a different subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104039#M10130</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Folks,&lt;/P&gt;&lt;P&gt;We have a local company network that uses the subnet 192.168.0.1/23 in our office.&amp;nbsp; All devices, domain controllers, etc are on this subnet as are all the office laptops, wifi, etc.&amp;nbsp; We have about 30 site to site VPN's created from our Checkpoint 5100's&amp;nbsp; that have our encryption domain as 172.16.3.0/24.&amp;nbsp; What we would like to do is to allow some of the users in the 192.168.0./23 subnet the ability to get an IP address in the 172.16.3.0/24 network so they can access devices on the remote site to site VPNs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since all of our users are on DHCP, what would be the easiest way to configure this on the 5100 Appliance? (R80.20) I was thinking NAT rules would be the simplest, but this would mean manually assigning IP addresses for all the users who need access.&amp;nbsp; &amp;nbsp;I also cannot change the encryption domain to&amp;nbsp; our office subnet (192.168.0.1/23) as I don't want everyone to have access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something here or does anyone have any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2020 17:48:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104039#M10130</guid>
      <dc:creator>Daniel_Bourne</dc:creator>
      <dc:date>2020-12-02T17:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: Configure encryption domain to allow specific users access from a different subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104087#M10131</link>
      <description>&lt;P&gt;What’s the topology behind the 5100 with respect to these two subnets?&lt;BR /&gt;I suspect static DHCP assignments plus NAT rules is probably the only way to do this.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 03:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104087#M10131</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-03T03:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Configure encryption domain to allow specific users access from a different subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104102#M10132</link>
      <description>&lt;P&gt;Behind the 5100, we have :&lt;/P&gt;&lt;P&gt;192.168.0.1/23&amp;nbsp; - office network, wifi, domain controllers, etc.&lt;/P&gt;&lt;P&gt;172.16.3.0/24 - Encryption domain for site to site VPNs&lt;/P&gt;&lt;P&gt;10.x.x.x - Engineering servers&lt;/P&gt;&lt;P&gt;Right now the way users access the encryption domain is by connecting to a local RRAS server which authenticates their account and gives them an IP on the 172.16.3.0/24 network (locally or remotely).&amp;nbsp; This then allows them to have access through some or all of the site to site VPN's using that encryption domain.&amp;nbsp; This is messy and we would like to get rid pf the RRAS server.&amp;nbsp; I know there is a lot going on here and I think it is more about improper network design, etc.&amp;nbsp; However, I was thinking there must be a way using our Checkpoint gateway to allow some users in 192.168.0.1/23 to use an IP in the 172.16.0.0/24 network.&amp;nbsp; You might be right about fixed IP's and NAT rules but that is a lot of work for me!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 08:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104102#M10132</guid>
      <dc:creator>Daniel_Bourne</dc:creator>
      <dc:date>2020-12-03T08:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Configure encryption domain to allow specific users access from a different subnet</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104275#M10133</link>
      <description>&lt;P&gt;If you're currently using RRAS to do it, you could achieve something similar with Remote Access VPN on the Check Point gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 23:07:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-encryption-domain-to-allow-specific-users-access-from/m-p/104275#M10133</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-03T23:07:49Z</dc:date>
    </item>
  </channel>
</rss>

