<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legacy Remote access solution with R80.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22002#M89851</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is applicable to end point VPN as well? Or only for mobile access policy? Yes I have community in the rule base.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should be done in that case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jan 2019 01:41:21 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2019-01-08T01:41:21Z</dc:date>
    <item>
      <title>Legacy Remote access solution with R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22000#M89849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again converting legacy policies to R80.10; here is one more issue would like to discuss. Previously I had legacy user access Remote Access VPN Solution [EPM].&lt;/P&gt;&lt;P&gt;Then edited the policy and ticked the Application Blade.&lt;/P&gt;&lt;P&gt;When&amp;nbsp;tried installing policy it threw an error about legacy user access group which was used for Remote VPN. Hence I created access role and added those groups in the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now policy installation was successful and even users were getting connected however one issue I faced was even though ports were allowed in the same rule. Traffic was dropping for Office mode client IPs to destination IPs which were present in the rule and it was dropping at the clean up rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue why? Then I again reverted the changes and it started working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rule#56&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Source - &lt;A href="mailto:RDPusers@Any"&gt;RDPusers@Any&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Dest - RDP_10.10.10.10&lt;/P&gt;&lt;P&gt;Service - TCP_3389&lt;/P&gt;&lt;P&gt;Action - Accept&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Rule#80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Any&lt;BR /&gt;Any&lt;/P&gt;&lt;P&gt;Drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So traffic was dropping at &lt;STRONG&gt;Rule#80&lt;/STRONG&gt; when &lt;STRONG&gt;Rule#56&lt;/STRONG&gt; was converted to&lt;/P&gt;&lt;P&gt;Source -&lt;SPAN&gt;&amp;nbsp;Access_Role_RDPUsers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Dest - RDP_10.10.10.10&lt;/P&gt;&lt;P&gt;Service - TCP_3389&lt;/P&gt;&lt;P&gt;Action - Accept&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 17:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22000#M89849</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2019-01-07T17:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Remote access solution with R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22001#M89850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you had a VPN community in the rule with access roles, this may have caused the drops, provided you were using "Unified Access Policy".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76747_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 18:57:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22001#M89850</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-01-07T18:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Remote access solution with R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22002#M89851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is applicable to end point VPN as well? Or only for mobile access policy? Yes I have community in the rule base.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should be done in that case?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 01:41:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22002#M89851</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2019-01-08T01:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy Remote access solution with R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22003#M89852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My understanding is that "Mobile Access Policy" is covering all remote access means and is run either in Legacy or Inline modes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the example of the policy I was using in one of my labs with Mobile Access layer:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/76754_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Access Roles configured according to your client of preference and the VPN column set to Any.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 04:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Legacy-Remote-access-solution-with-R80-10/m-p/22003#M89852</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-01-08T04:57:41Z</dc:date>
    </item>
  </channel>
</rss>

