<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: End users can't access local network when VPN connected to us. in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88252#M2391</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; we have a very similar scenario like this with our VPN client these days.&lt;/P&gt;&lt;P&gt;For few ips on some users systems there are multiple entries in their route tables, We don't want that traffic to go over vpn so that ip is not in tunnel encryption domain and still those ip's are showing up in route table.&lt;/P&gt;&lt;P&gt;This is causing the issues with the websites getting error as took too long to load. Now i can manually delete those entries and the site loads up fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the query is what might be causing the issue here? The batch file script which you shared it can work if we've few know ip's but this issue with multiple sites and is there any reason it might happen?&lt;/P&gt;&lt;P&gt;I've attached a snip of working and not working scenario where left section is of working system and right one is not working scenario. Any help would be really helpful.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Thu, 11 Jun 2020 14:52:39 GMT</pubDate>
    <dc:creator>Saagarg007</dc:creator>
    <dc:date>2020-06-11T14:52:39Z</dc:date>
    <item>
      <title>End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26072#M572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have overlapping IP ranges between a supplier and us. Once they connect to us they can no longer access their printers etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client is running Endpoint security E80.81. Firewalls running R77.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Connection Details&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;User Name RXXXX &lt;BR /&gt;IP 69.159.XXX.XX&lt;BR /&gt;VPN Gateway hfpXna_gateway_cluster &lt;BR /&gt;Client Type Other &lt;BR /&gt;Connect Time 1:50:59 PM 9/11/2018 &lt;BR /&gt;SCV State Unknown &lt;BR /&gt;Version &lt;BR /&gt;Operating System &lt;BR /&gt;Build Number &lt;BR /&gt;Last SCV Fail Reason &lt;BR /&gt;Internal IP 192.168.245.160 &lt;BR /&gt;Authentication Method XAUTH &lt;BR /&gt;Encryption Algorithm ESP3DES &lt;BR /&gt;Visitor Mode False &lt;BR /&gt;Route traffic False &lt;BR /&gt;UDP Encapsulation NATT &lt;BR /&gt;Office Mode True&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how to work around this. Way back in the past we fixed this by making a batch file that the user could run to change their routes to point the conflicting 10 network to their local gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody know of a better way to handle this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 18:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26072#M572</guid>
      <dc:creator>David_Won</dc:creator>
      <dc:date>2018-09-11T18:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26073#M573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try to exclude the IP addresses of their printers from your Remote access VPN Domain object?&amp;nbsp; If you have a network subnet defined on your gateway properties, then you might want to switch to a group containing network subnets/ip address ranges&amp;nbsp;instead&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 15:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26073#M573</guid>
      <dc:creator>Jason_Dance</dc:creator>
      <dc:date>2018-09-24T15:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26074#M574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Short of changing your own encryption domain to exclude the relevant IP addresses, you're pretty much limited to the batch script.&lt;/P&gt;&lt;P&gt;Years ago, I wrote my own script for this, documented in this thread:&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/5919-route-vpn-client-remote-access-to-lan" target="_blank"&gt;https://community.checkpoint.com/thread/5919-route-vpn-client-remote-access-to-lan&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:14:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26074#M574</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26075#M575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Preferably redesign your network in such a way that you only need public IP's for VPN purposes.&lt;/P&gt;&lt;P&gt;That is the only way to avoid overlaps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing some creative NATting might be a workaround.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 09:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/26075#M575</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-09-25T09:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88252#M2391</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; we have a very similar scenario like this with our VPN client these days.&lt;/P&gt;&lt;P&gt;For few ips on some users systems there are multiple entries in their route tables, We don't want that traffic to go over vpn so that ip is not in tunnel encryption domain and still those ip's are showing up in route table.&lt;/P&gt;&lt;P&gt;This is causing the issues with the websites getting error as took too long to load. Now i can manually delete those entries and the site loads up fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the query is what might be causing the issue here? The batch file script which you shared it can work if we've few know ip's but this issue with multiple sites and is there any reason it might happen?&lt;/P&gt;&lt;P&gt;I've attached a snip of working and not working scenario where left section is of working system and right one is not working scenario. Any help would be really helpful.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Jun 2020 14:52:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88252#M2391</guid>
      <dc:creator>Saagarg007</dc:creator>
      <dc:date>2020-06-11T14:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88287#M2394</link>
      <description>The routes that get propagated to a Remote Access client are a function of the IPs in a RemoteAccess Encryption Domain.&lt;BR /&gt;If they're not in the RemoteAccess Encryption Domain (either directly or indirectly), they won't get routes to those IPs.&lt;BR /&gt;I believe you can use "groups with exclusions" to exclude specific IPs.&lt;BR /&gt;&lt;BR /&gt;The script I provided is for an end user to potentially work around this issue without changing the encryption domain for everyone.&lt;BR /&gt;The proper "fix" for this is to change the encryption domain accordingly.&lt;BR /&gt;&lt;BR /&gt;In any case, if you feel you have configured this correctly and it's not working, please engage with the TAC.</description>
      <pubDate>Thu, 11 Jun 2020 19:44:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88287#M2394</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-11T19:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88295#M2396</link>
      <description>&lt;P&gt;Thanks for getting back on this query, i've checked a few time remoteaccess encryption domain and couldn't find those ip's in there. I've a TAC case already opened up so hopefully they should be able to find the cause of this.&lt;/P&gt;&lt;P&gt;Was just curious on this "groups with exclusion" do we create them in encryption domain itself?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 20:01:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88295#M2396</guid>
      <dc:creator>Saagarg007</dc:creator>
      <dc:date>2020-06-11T20:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88307#M2398</link>
      <description>The IP could be covered as part of a network in your encryption domain.&lt;BR /&gt;A group with exclusions could be used as the Remote Access encryption domain to exclude those IPs.</description>
      <pubDate>Fri, 12 Jun 2020 00:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/88307#M2398</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-12T00:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: End users can't access local network when VPN connected to us.</title>
      <link>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/95664#M2597</link>
      <description>&lt;P&gt;I had this same problem, and I solved it&amp;nbsp;with &lt;A title="sk121766" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121766&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank" rel="noopener"&gt;sk121766&lt;/A&gt;.&lt;BR /&gt;I hope it helps you.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 12:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/End-users-can-t-access-local-network-when-VPN-connected-to-us/m-p/95664#M2597</guid>
      <dc:creator>Rodrigo_Silva</dc:creator>
      <dc:date>2020-08-31T12:40:41Z</dc:date>
    </item>
  </channel>
</rss>

