<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec RAVPN: Restrict a Subnet from Connecting to the VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26676#M2090</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am gathering some helpful information for a while now to suffice my concern.&lt;/P&gt;&lt;P&gt;I found this thread and followed it but it does shows what I wanted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/7204-restricting-remote-access-by-ipv4-address" target="_blank"&gt;https://community.checkpoint.com/thread/7204-restricting-remote-access-by-ipv4-address&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is, I want to restrict a subnet from connecting to the VPN. For example, SUBNET-A should be the only subnet that can connect to my VPN using Endpoint VPN client. I tried in my lab what is in the link but I still can connect to VPN even though my endpoint does not belong to that subnet.&lt;/P&gt;&lt;P&gt;Is this really possible?&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2019 09:14:23 GMT</pubDate>
    <dc:creator>fatalXerror</dc:creator>
    <dc:date>2019-06-21T09:14:23Z</dc:date>
    <item>
      <title>IPSec RAVPN: Restrict a Subnet from Connecting to the VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26676#M2090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am gathering some helpful information for a while now to suffice my concern.&lt;/P&gt;&lt;P&gt;I found this thread and followed it but it does shows what I wanted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/7204-restricting-remote-access-by-ipv4-address" target="_blank"&gt;https://community.checkpoint.com/thread/7204-restricting-remote-access-by-ipv4-address&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My concern is, I want to restrict a subnet from connecting to the VPN. For example, SUBNET-A should be the only subnet that can connect to my VPN using Endpoint VPN client. I tried in my lab what is in the link but I still can connect to VPN even though my endpoint does not belong to that subnet.&lt;/P&gt;&lt;P&gt;Is this really possible?&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:14:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26676#M2090</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-06-21T09:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec RAVPN: Restrict a Subnet from Connecting to the VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26677#M2091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible - but what is shown in logs for you ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 13:10:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26677#M2091</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-23T13:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec RAVPN: Restrict a Subnet from Connecting to the VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26678#M2092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi @Günther W. Albrecht,&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my logs, i can only see "Key Install" and "Login" logs but these logs upon analyzing, it is pertaining to the VPN IP so the security rules will not to take effect. Is my understanding correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="233" src="https://community.checkpoint.com/legacyfs/online/checkpoint/77551_pastedImage_1.png" width="275" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Above image is a sample, I am connecting to my external zone (sorry the object naming is incorrect).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How I can restrict a group of user like only the group of 10.10.10.0/24 can connect to the VPN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 13:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26678#M2092</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2019-01-23T13:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec RAVPN: Restrict a Subnet from Connecting to the VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26679#M2093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What, if anything, did you try from that the thread you mentioned?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2019 04:42:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-RAVPN-Restrict-a-Subnet-from-Connecting-to-the-VPN/m-p/26679#M2093</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-26T04:42:47Z</dc:date>
    </item>
  </channel>
</rss>

