<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPn Remote Access. Issue with implied rule in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272395#M103766</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;What version and hotfix are installed? Cluster or single gateway?&lt;BR /&gt;&lt;BR /&gt;What message does the Endpoint client gets? What does SmartLog show?&lt;BR /&gt;&lt;BR /&gt;Can you test the complete VPN configuration by putting the Endpoint client directly on the external network of the gateway? So without NATed IP. This way you can check the Remote Access configuration is OK.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2026 16:49:58 GMT</pubDate>
    <dc:creator>Martijn</dc:creator>
    <dc:date>2026-03-03T16:49:58Z</dc:date>
    <item>
      <title>VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272390#M103764</link>
      <description>&lt;P&gt;I am trying to configure Remote Access VPN on a recently created R82 cluster, but it is not working and I am not sure why.&lt;/P&gt;&lt;P&gt;The Endpoint client is not able to establish the connection. I can see the connection attempts hitting the firewall, but they are being dropped (they should be accepted by the implicit rules).&lt;/P&gt;&lt;P&gt;I also created an explicit Access Control rule allowing traffic from the public IP address, but I am experiencing the same issue — the firewall does not respond to the connection attempts.&lt;/P&gt;&lt;P&gt;Regarding the configuration:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The external interface has a private IP address configured.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Under &lt;STRONG&gt;IPSec VPN → Link Selection&lt;/STRONG&gt;, I selected &lt;STRONG&gt;Statically NATed IP&lt;/STRONG&gt; and configured the public IP address that is directly NATed to the firewall.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;I verified that the Platform Portal is configured with a specific IP address for connections.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Mobile Access Blade portal is configured with the same public IP address defined in Link Selection.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Does anyone have any idea what could be causing this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 16:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272390#M103764</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2026-03-03T16:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272394#M103765</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;could you share some screenshot of your configuration? (in particular the settings in the VPN clients section within the gateway), just to try to help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 16:46:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272394#M103765</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-03T16:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272395#M103766</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;What version and hotfix are installed? Cluster or single gateway?&lt;BR /&gt;&lt;BR /&gt;What message does the Endpoint client gets? What does SmartLog show?&lt;BR /&gt;&lt;BR /&gt;Can you test the complete VPN configuration by putting the Endpoint client directly on the external network of the gateway? So without NATed IP. This way you can check the Remote Access configuration is OK.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 16:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272395#M103766</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-03-03T16:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272401#M103768</link>
      <description>&lt;P&gt;Its a cluster in R82 With take 60.&lt;/P&gt;&lt;P&gt;The message in the Endpoint said there is unable to connect with the site (During the site creation step). And the SmartLog shows how the firewall drops the comunnication, in other environments that comunications are accepted by implied rules. I also try to create a explicit rule to accept the traffic but without succesfull.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a good approach to test the connectivity directly but i need to ask if it is possible... currently i only have access remotly&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 17:44:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272401#M103768</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2026-03-03T17:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272403#M103769</link>
      <description>&lt;P&gt;In the configuration I allowed the connection from the following:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN.png" style="width: 275px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33565i731431E33B7A9C06/image-dimensions/275x210?v=v2" width="275" height="210" role="button" title="VPN.png" alt="VPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the authenticator method is RADIUS (but well the issue is during the site creation, is like the firewall doesnt associate the Nated IP configured with the VPN service or his internal network...). I have compared the configuration with other environments and everythings seems to be configured correctly &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 17:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272403#M103769</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2026-03-03T17:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272412#M103775</link>
      <description>&lt;P&gt;Did you add the gateway to the remote access community?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 18:30:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272412#M103775</guid>
      <dc:creator>Jesusm</dc:creator>
      <dc:date>2026-03-03T18:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272415#M103777</link>
      <description>&lt;P&gt;Yes, I also have another firewall in remote access community (that is working fine with a similar scenario) but I understand that doesnt affect with the comunication of the new remote access right? At the end each gateway has their own VPN domain configured.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 18:51:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272415#M103777</guid>
      <dc:creator>Vanesa_Benito_O</dc:creator>
      <dc:date>2026-03-03T18:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272458#M103793</link>
      <description>&lt;P&gt;Usually if you have two different gateways (Gateway A and Gateway B) in the same Remote Access community, for my experience, you need to edit $FWDIR/conf/trac_client_1.ttm file on the gateways and change configuration about MEP related to these lines setting the default to false:&lt;/P&gt;&lt;P&gt;:automatic_mep_topology (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:false (false)&lt;BR /&gt;:true (true)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;:default (false)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe is not your case (in this case ignore my post), but I always performed this configuration, withtout it the client connect to Gateway A and it's redirected to Gateway B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 08:27:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272458#M103793</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-04T08:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPn Remote Access. Issue with implied rule</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272462#M103797</link>
      <description>&lt;P&gt;When the firewall is dropping the packets, what is the 'drop reason' in the log?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 08:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPn-Remote-Access-Issue-with-implied-rule/m-p/272462#M103797</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-04T08:37:00Z</dc:date>
    </item>
  </channel>
</rss>

