<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Organization of Internet access via a remote gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171859#M31223</link>
    <description>&lt;P&gt;As you should know, R77.30 is out of support for a time now... It does make no sense to me to send traffic for UserPC2 thru VPN to Site 2 and thru TP to the internet as this will slow down traffic ! Why not go from GW3 using R81.10 TP to the internet ? Server access can be regulated using rules, so why use two VPN Domains at all ?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 10:02:31 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-02-17T10:02:31Z</dc:date>
    <item>
      <title>Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171843#M31220</link>
      <description>&lt;P&gt;Hello colleagues!&lt;/P&gt;&lt;P&gt;Please help me understand how this scheme can be implemented?&lt;/P&gt;&lt;P&gt;There is an SMS Gaia R81.10 which manages three gateways:&lt;BR /&gt;GW1 - R77.30&lt;BR /&gt;GW2 - R77.30&lt;BR /&gt;GW3 - R81.10&lt;/P&gt;&lt;P&gt;User PC1, which is on the network behind GW3, has access to the Server, which is on the network behind GW1 via Site-to-Site VPN.&lt;/P&gt;&lt;P&gt;How can I make the second User PC2 machine (in same subnet) access the Internet via GW2 and not have access to the Server?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19654i3E6C9C8D2A25D27B/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 08:39:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171843#M31220</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T08:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171848#M31221</link>
      <description>&lt;P&gt;By using firewall rules ! If you know the User PCs IPs this is rather simple; but you could also use IA for a large client number.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 09:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171848#M31221</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T09:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171855#M31222</link>
      <description>&lt;P&gt;Yes, but how to make traffic for UserPC2 to the Internet go through GW2?&lt;BR /&gt;So far I've figured out what to do with two VPN Communities, for example:&lt;BR /&gt;1. Mesh Community - GW3+GW1&lt;BR /&gt;2. Star Community - GW2 (Center) + GW1 (Satellite)&lt;BR /&gt;&lt;BR /&gt;and VPN Routing&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.JPG" style="width: 665px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19656i40C79A8CF4A0E0A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;But at the same time the connection between GW3 and GW1 disappears&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 09:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171855#M31222</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T09:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171859#M31223</link>
      <description>&lt;P&gt;As you should know, R77.30 is out of support for a time now... It does make no sense to me to send traffic for UserPC2 thru VPN to Site 2 and thru TP to the internet as this will slow down traffic ! Why not go from GW3 using R81.10 TP to the internet ? Server access can be regulated using rules, so why use two VPN Domains at all ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:02:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171859#M31223</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T10:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171860#M31224</link>
      <description>&lt;P&gt;That is, need to:&lt;/P&gt;&lt;P&gt;It is necessary that PC1 traffic goes&lt;BR /&gt;PC1-&amp;gt;GW3-&amp;gt;GW1-&amp;gt;Server&lt;/P&gt;&lt;P&gt;At the same time , PC2 traffic was going&lt;BR /&gt;PC2-&amp;gt;GW3-&amp;gt;GW2-&amp;gt;Internet&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:02:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171860#M31224</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T10:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171862#M31225</link>
      <description>&lt;P&gt;The main reason is for the machine PC2 to have internet access under a certain white ip i.e. via GW2&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:07:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171862#M31225</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T10:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171864#M31226</link>
      <description>&lt;P&gt;What is a white IP ? Usually, you are NATing clients behind the GW IP. Do you want to change the clients source country using VPN or a similar trick to achive what ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:13:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171864#M31226</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T10:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171865#M31227</link>
      <description>&lt;P&gt;By white ip, I mean the external ip address of the gateway GW2.&lt;BR /&gt;Yes, the goal is to change the country for the client.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171865#M31227</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T10:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171866#M31228</link>
      <description>&lt;P&gt;I strongly have to warn you that such an action is mostly taken for criminal reasons ! At least i did not yet encounter honest reasons for such a demand except for undercover police forces &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171866#M31228</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T10:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171868#M31229</link>
      <description>&lt;P&gt;OK, I'll take that into consideration, but I think it's irrelevant.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 10:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171868#M31229</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T10:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171876#M31230</link>
      <description>&lt;P&gt;Sorry, i do not understand your answer ! Why is that irrelevant if we take performance from 2 GWs for RA VPN that is only needed to hide the clients source country ? And why hide it at all ? To cheat CP GeoLocation rules and be able to attack ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 11:14:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171876#M31230</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T11:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171877#M31231</link>
      <description>&lt;P&gt;I have no purpose to use this option for illegal purposes.&lt;BR /&gt;In addition, there are simpler ways to do this.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 11:25:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171877#M31231</guid>
      <dc:creator>Sergey_Anikeev</dc:creator>
      <dc:date>2023-02-17T11:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Organization of Internet access via a remote gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171880#M31232</link>
      <description>&lt;P&gt;Very good, but why use this option at all ? Simplest way is RA VPN wire mode to GW2. But i would suggest to upgrade the R77.30 GWs first !&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 12:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Organization-of-Internet-access-via-a-remote-gateway/m-p/171880#M31232</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T12:21:14Z</dc:date>
    </item>
  </channel>
</rss>

