<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CloudGuard - Remote Access SSL-VPN Connectivity Issues. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182477#M33456</link>
    <description>&lt;P&gt;Yes, this guide is specifically for &lt;STRONG&gt;Scale Sets&lt;/STRONG&gt;. Which makes use of the Azure Functions to return the active member's public IP address to the connecting client.&lt;/P&gt;&lt;P&gt;In case of single gateway, the public IP address associated with the external interface will be used for VPN. And for HA the cluster's public VIP address will be used.&lt;/P&gt;&lt;P&gt;Reference Architecture:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk109360#" target="_blank"&gt;Check Point Reference Architecture for Azure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, it's not about the network reachability but the gateway is refusing the connection for "&lt;STRONG&gt;https://&amp;lt;gateway-public-ip&amp;gt;/sslvpn&lt;/STRONG&gt;" URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 07:42:11 GMT</pubDate>
    <dc:creator>chethan_m</dc:creator>
    <dc:date>2023-05-30T07:42:11Z</dc:date>
    <item>
      <title>CloudGuard - Remote Access SSL-VPN Connectivity Issues.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182462#M33450</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm practicing deploying CloudGuard Network Security Solution on Azure Public Cloud and I'm facing connectivity issues with setting up Remote-Access VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the web-browser, I can see that the gateway is resetting the connection: &lt;STRONG&gt;"It looks like&amp;nbsp;&lt;FONT color="#000000"&gt;&amp;lt;GW-Pub-IP-Addr&amp;gt;&lt;/FONT&gt;&amp;nbsp;closed the connection&lt;/STRONG&gt;&amp;nbsp;-&amp;gt; &lt;STRONG&gt;ERR_CONNECTION_&lt;/STRONG&gt;&lt;STRONG&gt;CLOSED"&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Architecture:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CloudGuard Single Gateway deployed with 2 interfaces: eth0 and eth1. The static public IP is assigned to eth0:1 sub-interface.&lt;/LI&gt;&lt;LI&gt;The SMS is on an on-premise VMware Workstation.&lt;/LI&gt;&lt;LI&gt;IPsec VPN and Mobile Access VPN blades are enabled on the gateway.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I followed this SK article: &lt;I&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk109360#" target="_blank" rel="noopener"&gt;Check Point Reference Architecture for Azure&lt;/A&gt;&lt;/I&gt;. The best practices section speaks about the &lt;STRONG&gt;IPsec VPN, Link Selection Source IP Address&amp;nbsp;settings&lt;/STRONG&gt;, where it says to select the private IP address of the gateway's external interface to&amp;nbsp;&lt;SPAN&gt;ensure that the Gateway in the Azure cloud sends encrypted traffic with the source address set to its private IP address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is there anything similar to do for Remote Access VPN configuration as well?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Anti-Spoofing is disabled on both external and internal interfaces.&lt;/LI&gt;&lt;LI&gt;I suspected there might be a conflict with Web-UI and changed the &lt;STRONG&gt;web ssl-port&lt;/STRONG&gt; from 443 to 4434. Even then the issue persists.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could anyone help me to know what should I be troubleshooting for, please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 09:25:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182462#M33450</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-05-31T09:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard - Remote Access SSL-VPN Connectivity Issues.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182475#M33455</link>
      <description>&lt;P&gt;Did you read &lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Content/Topics-Azure-VMSS/Overview.htm#Remote_Access_VPN_..2" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_VMSS_for_Azure/Content/Topics-Azure-VMSS/Overview.htm#Remote_Access_VPN_..2&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 06:57:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182475#M33455</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-30T06:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard - Remote Access SSL-VPN Connectivity Issues.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182477#M33456</link>
      <description>&lt;P&gt;Yes, this guide is specifically for &lt;STRONG&gt;Scale Sets&lt;/STRONG&gt;. Which makes use of the Azure Functions to return the active member's public IP address to the connecting client.&lt;/P&gt;&lt;P&gt;In case of single gateway, the public IP address associated with the external interface will be used for VPN. And for HA the cluster's public VIP address will be used.&lt;/P&gt;&lt;P&gt;Reference Architecture:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk109360#" target="_blank"&gt;Check Point Reference Architecture for Azure&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, it's not about the network reachability but the gateway is refusing the connection for "&lt;STRONG&gt;https://&amp;lt;gateway-public-ip&amp;gt;/sslvpn&lt;/STRONG&gt;" URL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 07:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182477#M33456</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-05-30T07:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard - Remote Access SSL-VPN Connectivity Issues.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182482#M33457</link>
      <description>&lt;P&gt;Better contact CP TAC - MAB is supported with Azure, but i did not find any special configuration hints. Changing the WebUI port should not be needed as MAB uses the path /sslvpn for access (MultiPortal feature).&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 08:34:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182482#M33457</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-05-30T08:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: CloudGuard - Remote Access SSL-VPN Connectivity Issues.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182658#M33494</link>
      <description>&lt;P&gt;The solution to my problem was found here (sk115732):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk115732" target="_blank" rel="noopener"&gt;Unable to connect to Gaia Portal on port 443 (checkpoint.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 09:26:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CloudGuard-Remote-Access-SSL-VPN-Connectivity-Issues/m-p/182658#M33494</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-05-31T09:26:23Z</dc:date>
    </item>
  </channel>
</rss>

