<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limited Remote VPN access in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146539#M5536</link>
    <description>&lt;P&gt;Wow Danny! it works! unbelievable!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Apr 2022 23:32:20 GMT</pubDate>
    <dc:creator>Sergo89</dc:creator>
    <dc:date>2022-04-19T23:32:20Z</dc:date>
    <item>
      <title>Limited Remote VPN access</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146491#M5528</link>
      <description>&lt;P&gt;Hi Everybody,&lt;/P&gt;&lt;P&gt;I need to configure a limited remote access via Endpoint client, for example Group A (windows group) has Full access to all internal network and Group B just to one subnet. I configured like that (still not sure does it work properly or not)&lt;/P&gt;&lt;P&gt;Source: Access Role with LDAP group (here i use Group A or B)&lt;/P&gt;&lt;P&gt;Dest: All internal networks for Group A or another rule - one subnet for group B&lt;/P&gt;&lt;P&gt;VPN: RemoteAccess Community&lt;/P&gt;&lt;P&gt;Services: all&lt;/P&gt;&lt;P&gt;It works for my Primary firewall, i had problem before - we have to use OfficeMode (i know its requirements for Full Endpoint Client), and sometimes its stop working, because OfficeMode means all remote clients have IP addresses and technically its standard network, and has to following standard firewall rules (add OfficeMode network to rules like source). But for my second firewall this schema doesnt work, i havet create rule - source OfficeMode Net - Dest - Internal networks, but with this rule, all my previous rules&amp;nbsp; (Access Roles etc) totally useless, Group A and B have same full access.&lt;/P&gt;&lt;P&gt;Any idea how to configure it properly?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146491#M5528</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-04-19T14:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Remote VPN access</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146497#M5530</link>
      <description>&lt;P&gt;I'd start with something like this on your primary firewall:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16086i359F228656235624/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As you can see this doesn't allow a separation of OfficeMode IPs for RAS Group A and B.&lt;BR /&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt; (&lt;EM&gt;also for your second firewall&lt;/EM&gt;) :&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422" target="_self"&gt;&lt;SPAN&gt;sk33422 -&amp;nbsp;Office Mode IP and ipassignment.conf file&lt;/SPAN&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This allows you to assign specific IP addresses of your Office Mode Pool to users of RAS VPN Group B.&lt;/SPAN&gt;&lt;BR /&gt;Then you can create two new subnet objects '&lt;EM&gt;OfficeMode1&lt;/EM&gt;' and '&lt;EM&gt;OfficeMode2&lt;/EM&gt;' and use them in your rulebase (&lt;EM&gt;leave the original OfficeMode object as it is&lt;/EM&gt;).&lt;/P&gt;
&lt;P&gt;Result:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 965px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16087i57F372992C6A2E4D/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 06:19:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146497#M5530</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-04-20T06:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: Limited Remote VPN access</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146539#M5536</link>
      <description>&lt;P&gt;Wow Danny! it works! unbelievable!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 23:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Limited-Remote-VPN-access/m-p/146539#M5536</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2022-04-19T23:32:20Z</dc:date>
    </item>
  </channel>
</rss>

