<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Gateway Proxy Mode Configuration in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22202#M4196</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could use CP Professional Services to do the configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2018 11:01:54 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-05-09T11:01:54Z</dc:date>
    <item>
      <title>Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22197#M4191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;We have ad environment and checkpoint is in cluster OS Gaia R80.10.&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We wanted to configure ad authentication and also enable checkpoint gateway as a non-transparent proxy .&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found below SK sk123673 &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;:- Redirection to Captive Portal is not working when Security Gateway is configured as proxy&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I configure Proxy with authentication or single sign on &lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="min-height: 8pt; padding: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 11:06:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22197#M4191</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2018-05-08T11:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22198#M4192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Also we wanted to user SSL VPN so in this case gateway mode and proxy mode both mode is require &lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 11:07:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22198#M4192</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2018-05-08T11:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22199#M4193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not fully understand your question - sk123673 tells us that for customers who want to use R80.10 GW as a non-transparent proxy and UserCheck needs a special Hotfix from CP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i also have to add that using the GW as a proxy can have side effects (and it has a lot of other things to do ;-), so i always prefer squid on a server as a proxy!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 11:55:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22199#M4193</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-08T11:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22200#M4194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Exact need is below From COMPANY A without disturbing topology of Company B &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1" style="margin-top:0in;" type="A"&gt;&lt;LI style="margin-left:0in;mso-list:l0 level1 lfo1;"&gt; &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;Checkpoint Gateway In Proxy Mode (Explicit Proxy )&lt;/LI&gt;&lt;LI style="margin-left:0in;mso-list:l0 level1 lfo1;"&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;AD authentication &lt;/LI&gt;&lt;LI style="margin-left:0in;mso-list:l0 level1 lfo1;"&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;SSL VPN &lt;/LI&gt;&lt;LI style="margin-left:0in;mso-list:l0 level1 lfo1;"&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;IP based Internet and MPLS Connectivity .&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Present Setup &lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;MPLS A and MPLS B is connected with L3 Switch &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Presently Users Of Company B &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;and Company A are using internet through MPLS B &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;==&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;LAN USER &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;configured with Proxy &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; L3 Switch&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; MPLS B&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Internet of Company B ( Different GEO Location )&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;== LAN User Who wanted to use Application behind mpls A &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; L3 &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; MPLS A&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Application Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In lan side user which is behind l3 Switch (some users is related to Company A and Some users are Company B ) In same lan connectivity .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Scenario after checkpoint comes in topology &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User A want internet from checkpoint &lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&lt;/SPAN&gt;=&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;User Company A -&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; L3 Switch -&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Checkpoint Firewall -&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Internet (ISP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User B want internet from MPLS B&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;= User company B &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; L3 Switch &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; MPLS B -&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Internet of Company B ( Different GEO Location )&lt;SPAN style="mso-spacerun:yes;"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;== LAN User Who wanted to use Application behind mpls A &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; L3 &lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; MPLS A&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-hansi-font-family: Calibri; font-family: Wingdings; mso-ascii-font-family: Calibri; mso-char-type: symbol;"&gt;à&lt;/SPAN&gt; Application Server&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This all we need in one cluster (Two Checkpoint Gateway ) With R80.10 OS and MGMT IN VM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I'm thinking to do proxy for Company A because we cannot forward default traffic to checkpoint firewall from L3 Switch to entering default route. We can user specific host route and achieve proxy setup &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2018 12:20:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22200#M4194</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2018-05-08T12:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22201#M4195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Please help me to solve this issue .&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 09:48:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22201#M4195</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2018-05-09T09:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22202#M4196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could use CP Professional Services to do the configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 11:01:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22202#M4196</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-09T11:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Proxy Mode Configuration</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22203#M4197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a situation where you'd probably want to use VSX.&lt;/P&gt;&lt;P&gt;Each company would be provided a virtual firewall, each of which could have a different default route without using a proxy.&lt;/P&gt;&lt;P&gt;The authentication piece should probably be done with Identity Awareness (specifically Identity Collector) without using Captive Portal, especially if AD is involved.&lt;/P&gt;&lt;P&gt;More info here:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_IdentityAwareness_AdminGuide/html_frameset.htm"&gt;Identity Awareness R80.10 Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 13:58:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Checkpoint-Gateway-Proxy-Mode-Configuration/m-p/22203#M4197</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-09T13:58:02Z</dc:date>
    </item>
  </channel>
</rss>

