<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic between 2 users connected to Remote Access. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109742#M20811</link>
    <description>&lt;P&gt;Sure I may have made it sound more impressive than it actually is, the DNS update is just done via a call to gpupdate:&lt;/P&gt;&lt;P&gt;@echo off&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo ** **&lt;BR /&gt;echo ** Please wait while we connect you **&lt;BR /&gt;echo ** **&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo **************************************&lt;BR /&gt;ping 127.0.0.1 -n 5 &amp;gt; nul&lt;BR /&gt;gpupdate /wait:0&lt;BR /&gt;WMIC /namespace:\\root\ccm path sms_client CALL TriggerSchedule "{00000000-0000-0000-0000-000000000003}" /NOINTERACTIVE&lt;BR /&gt;@echo on&lt;BR /&gt;exit&lt;/P&gt;</description>
    <pubDate>Wed, 03 Feb 2021 21:56:25 GMT</pubDate>
    <dc:creator>Gareth_somers</dc:creator>
    <dc:date>2021-02-03T21:56:25Z</dc:date>
    <item>
      <title>Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78146#M15914</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a simple question, is possible to allow 2 users connected through Remote Access in the same Gateway to talk each other? I am trying to ping another Laptop connected in RA but I cannot but I can ping both devices from internal LAN. Thanks!&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 19:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78146#M15914</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2020-03-12T19:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78181#M15923</link>
      <description>&lt;P&gt;Technically, with Office Mode IP addresses, VPN routing through GW is possible. However, these IP assignments are dynamic, hence in practice it is really hard to achieve.&lt;BR /&gt;&lt;BR /&gt;So, the practical answer is, most probably no&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 08:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78181#M15923</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-13T08:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78182#M15924</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for your answer. IPs being assigned dynamically is not a problem, the thing is that we need that two users connected to RA VPN access, should be able to talk using Cisco Jabber, so I need IP connectivity between these users.&amp;nbsp; I have select the Hub Mode option (Allow VPN Clients to route traffic through this gateway) but it does not work :-(. I think that there should be a solution for this, two remote users being able to call and talk each other using VoIP is not an uncommon scenario.&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 08:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78182#M15924</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2020-03-13T08:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78194#M15927</link>
      <description>&lt;P&gt;Check you have specifically allow Jabber connectivity through VPN tunnel.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 10:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78194#M15927</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-13T10:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78219#M15939</link>
      <description>&lt;P&gt;You probably need to add the Office Mode network to the VPN Domain of the gateway.&amp;nbsp; If that doesn't help, double check the traffic logs and see if it gives an indication as to why this doesn't work.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 15:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78219#M15939</guid>
      <dc:creator>Bob_Bumpus1</dc:creator>
      <dc:date>2020-03-13T15:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78541#M15991</link>
      <description>&lt;P&gt;Yes, I have added the network in the VPN Domain for Remote Access and I even add a rule to permit traffic between remote access pool network and remote access pool network .&lt;/P&gt;&lt;P&gt;The thing is that I have the same scenario on a Cisco ASA and it works, two users connected to RA VPN are able to call each other using Jabber.&lt;/P&gt;&lt;P&gt;Looking the Checkpoint Logs, I cannot find anything related this traffic but I can see that my PC is sending the traffic to the firewall when I try to reach another user connected to RA VPN. I was able to see it using Wireshark. There is something in the Checkpoint which is dropping this traffic silently but I cannot find the reason &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 12:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/78541#M15991</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2020-03-17T12:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109622#M20793</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/43412"&gt;@Gusa2727&lt;/a&gt; , were you ever able to find a solution to this issue? Looks like one of my clients with Jabber is looking to replace their AnyConnect solution with Check Point RA and I may run into same situation.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 01:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109622#M20793</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-02-03T01:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109623#M20794</link>
      <description>&lt;P&gt;I have in our environment this scenario, we use VPN Client 84.00 and Cisco Jabber, we call eatch other withou problem. Send me an e-mail, we can make a remote session in webex.&lt;/P&gt;&lt;P&gt;fernando.bvds@gmail.com&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 01:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109623#M20794</guid>
      <dc:creator>Fernandosilva</dc:creator>
      <dc:date>2021-02-03T01:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109655#M20800</link>
      <description>&lt;P&gt;There should be no issue, we allow Remote Access Clients to communicate with each other (Jabber, Remote access for ICT, etc.) without issue, We use Office Mode to assign IPs and a post connection script to update DNS in AD so they resolve correctly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We did see an issue with certain users (less then .2% of the user base) where SecureXL templates weren't being created correctly and Remote Access to Remote Access failed for them (so no ping, Jabber calls, SMB etc.) but access from the LAN worked fine.&amp;nbsp; Disabling SecureXL (fwaccel off) fixed this and once we moved to R80.40, we were able to reenable SecureXL without issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 10:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109655#M20800</guid>
      <dc:creator>Gareth_somers</dc:creator>
      <dc:date>2021-02-03T10:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109684#M20805</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13654"&gt;@Gareth_somers&lt;/a&gt; . Can you clarify few things for me:&lt;/P&gt;
&lt;P&gt;1. Are your remote clients using Secure Domain Logon (SDL)?&lt;/P&gt;
&lt;P&gt;2. Do you serve them IPs from AD DHCP or the Office mode range?&lt;/P&gt;
&lt;P&gt;3. Do you allow Reverse Lookup Zone in AD DNS to use Nonsecure and Secure updates?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it is not too much trouble, can you share the script or drop it to me in DM?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 13:22:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109684#M20805</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-02-03T13:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109689#M20806</link>
      <description>&lt;P&gt;1. Are your remote clients using Secure Domain Logon (SDL)?&lt;/P&gt;&lt;P&gt;No - We decided against this as a security risk, we didn't want the VPN up before the user was logged in.&amp;nbsp; Instead we use User Certs stored in their personal store so in order to connect to the network they must first authenticated.&lt;/P&gt;&lt;P&gt;2. Do you serve them IPs from AD DHCP or the Office mode range?&lt;/P&gt;&lt;P&gt;Originally we used DHCP from AD, however we do not have AD in the Datacenter that the Remote Access firewalls are located in and this meant traversing other firewalls and a VPN tunnel in order to get IPs. Given the dependency on this we moved to the firewalls providing IPs locally which meant that we had to add logic via a post connect script to update DNS (only secure DNS changes are allowed in our AD) and for updating GPOs.&lt;/P&gt;&lt;P&gt;3. Do you allow Reverse Lookup Zone in AD DNS to use Nonsecure and Secure updates?&lt;/P&gt;&lt;P&gt;Secure updates as above, this is handled via a script run post connection from the end users device.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 14:16:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109689#M20806</guid>
      <dc:creator>Gareth_somers</dc:creator>
      <dc:date>2021-02-03T14:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109729#M20809</link>
      <description>&lt;P&gt;I would start by checking the route table on RA client PC's when connected to RA VPN.&amp;nbsp; If the route to the Office Mode network is there then I suspect the voice issue may be NAT related.&amp;nbsp; I would look to see if there is a no-NAT rule for the Office Mode IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 20:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109729#M20809</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2021-02-03T20:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109731#M20810</link>
      <description>&lt;P&gt;The post connection script may be just the ticket I am looking for to address DNS inconsistency that has showed it's head from time to time in my environment.&amp;nbsp; Are you willing to share a 'cleaned' version of the script?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 20:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109731#M20810</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2021-02-03T20:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between 2 users connected to Remote Access.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109742#M20811</link>
      <description>&lt;P&gt;Sure I may have made it sound more impressive than it actually is, the DNS update is just done via a call to gpupdate:&lt;/P&gt;&lt;P&gt;@echo off&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo ** **&lt;BR /&gt;echo ** Please wait while we connect you **&lt;BR /&gt;echo ** **&lt;BR /&gt;echo **************************************&lt;BR /&gt;echo **************************************&lt;BR /&gt;ping 127.0.0.1 -n 5 &amp;gt; nul&lt;BR /&gt;gpupdate /wait:0&lt;BR /&gt;WMIC /namespace:\\root\ccm path sms_client CALL TriggerSchedule "{00000000-0000-0000-0000-000000000003}" /NOINTERACTIVE&lt;BR /&gt;@echo on&lt;BR /&gt;exit&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 21:56:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-between-2-users-connected-to-Remote-Access/m-p/109742#M20811</guid>
      <dc:creator>Gareth_somers</dc:creator>
      <dc:date>2021-02-03T21:56:25Z</dc:date>
    </item>
  </channel>
</rss>

