<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I can ping but I can't browse - vpn and proxy check point in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15541#M2628</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Plea specify the version of the Check Point Management and gateways, if you have proxy configured in transparent or explicit mode, if you have defined the interface for the proxy and if you are using .pac files on your VPN&amp;nbsp; clients.&lt;/P&gt;&lt;P&gt;Additionally, please clarify what kind of VPN are we talking about: SSL or the IPSec and if second, what VPN software client and version is in use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Dec 2017 19:27:24 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2017-12-01T19:27:24Z</dc:date>
    <item>
      <title>I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15540#M2627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone&lt;/P&gt;&lt;P&gt;I'm having some issues using the Check Point Gateway as a proxy when I'm using the check point client VPN.&lt;/P&gt;&lt;P&gt;Scenario is as follows: my gateway is configured as a proxy. Recently I activated VPN functionality. The vpn works normally, however, I can not navigate if I use the proxy check point but I can ping any site.&lt;/P&gt;&lt;P&gt;I made a test connected in another VPN that gives access to the same networks, I used the Check Point proxy again and the access was allowed or denied according to my ACLs and I can see it in my logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any limitation on using the gateway as vpn and proxy or should I make some configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 12:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15540#M2627</guid>
      <dc:creator>Kadu_Lincoln</dc:creator>
      <dc:date>2017-12-01T12:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15541#M2628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Plea specify the version of the Check Point Management and gateways, if you have proxy configured in transparent or explicit mode, if you have defined the interface for the proxy and if you are using .pac files on your VPN&amp;nbsp; clients.&lt;/P&gt;&lt;P&gt;Additionally, please clarify what kind of VPN are we talking about: SSL or the IPSec and if second, what VPN software client and version is in use.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 19:27:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15541#M2628</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-12-01T19:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15542#M2629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answer, Vladimir!&lt;/P&gt;&lt;P&gt;I'm using R80.10 in both: Mangament and gateway. Proxy is configured in Non Transparent mode. I did not define an interface for the proxy and in this firt moment I'm not using .pac file on VPN client.&lt;/P&gt;&lt;P&gt;I'm using IPSec with Check Point Endpoint Security E80.70&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2017 22:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15542#M2629</guid>
      <dc:creator>Kadu_Lincoln</dc:creator>
      <dc:date>2017-12-03T22:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15543#M2630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kadu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check if the VPN tunneling is enabled on your EndPoint Security clients, else you are looking at the split tunnel scenario, where not all traffic is being sent to the gateways.&lt;/P&gt;&lt;P&gt;Since you have mentioned that you can ping all the sites, (I presume from the client), try traceroute from the client to determine if your ICMP traffic is going over the VPN, or if it is going directly via local gateway of the remote client.&lt;/P&gt;&lt;P&gt;Additionally, it is a good idea to determine, using nslookup, where does the DNS resolution happening, locally or via VPN.&lt;/P&gt;&lt;P&gt;Next, confirm that you are offering "Office Mode" to remote users.&lt;/P&gt;&lt;P&gt;If yes, check the IP Pool that is being used for address allocation.&lt;/P&gt;&lt;P&gt;Make sure that you have a rule allowing the IP pool to access Internet and that it is being NATed on its way out.&lt;/P&gt;&lt;P&gt;You may also check "Optional Parameters" in the "Office Mode" to see what DNS servers are defined for remote clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Dec 2017 19:09:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15543#M2630</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-12-04T19:09:56Z</dc:date>
    </item>
    <item>
      <title>Re: I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15544#M2631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vladimir, is this option you referred to (VPN tunneling)? How can I change it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61234_pastedImage_3.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ICMP traffic is going directly via local gateway of my remote client.&lt;/P&gt;&lt;P&gt;DNS resolution is happening via VPN normally.&lt;/P&gt;&lt;P&gt;I'm offering "Office Mode" to remote users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61233_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61235_pastedImage_4.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Dec 2017 23:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15544#M2631</guid>
      <dc:creator>Frederico_Linco</dc:creator>
      <dc:date>2017-12-05T23:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: I can ping but I can't browse - vpn and proxy check point</title>
      <link>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15545#M2632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using a simple SecuRemote, you will not be able to change this:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SecuRemote" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61238_SecuRemote.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using a full EndPoint security, this should work:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Route Through Gateway Hub" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61239_VPN_Through_Gateway_Routing.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Provided the rules are in place to allow it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2017 01:57:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/I-can-ping-but-I-can-t-browse-vpn-and-proxy-check-point/m-p/15545#M2632</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2017-12-06T01:57:00Z</dc:date>
    </item>
  </channel>
</rss>

