<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RA clients not able to access external cluster interface in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253501#M42556</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just did some tests in my R82 lab, no issues. I have same option about external interface unchecked as you do, I simply made sure external interface IP is included in RA vpn domain, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sat, 19 Jul 2025 13:01:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-07-19T13:01:36Z</dc:date>
    <item>
      <title>RA clients not able to access external cluster interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253496#M42552</link>
      <description>&lt;P&gt;Good Day All,&lt;/P&gt;
&lt;P&gt;We have a challenge whereby re-authentication fails for our RA VPN clients.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Background:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Our VPN gateways (R81.20 T99 / SMS T105) are NAT'd behind perimeter gateways, so the VPN gateway "public" IP's are actually RFC1918 IP's (10.x.x.x). Furthermore, when connecting to the "internal" LAN you'll need to connect via VPN to access any resources, so external clients resolve vpn.domain.com to a public IP, and internal clients will resolve vpn.domain.com to an internal IP (external cluster interface on VPN gateways).&lt;/P&gt;
&lt;P&gt;Both internal and external clients can log into the VPN just fine - as per the SAML login process clients get redirected to &lt;A href="https://vpn.domain.com/saml-vpn" target="_blank" rel="noopener"&gt;https://vpn.domain.com/saml-vpn&lt;/A&gt; on either the NAT'd public IP of the perimeter gateways or the internal IP of the VPN gateway, depending on whether the RA client is inside or out.&lt;/P&gt;
&lt;P&gt;Clients completes authentication and life is good.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The problem&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The problem comes when their authentication expires (ours is set to 8h). The VPN client will attempt to re-auth by hitting &lt;A href="https://vpn.domain.com/saml-vpn" target="_blank" rel="noopener"&gt;https://vpn.domain.com/saml-vpn&lt;/A&gt; which now resolves to the internal (10.x.x.x) cluster IP. This is where we run into issues.&lt;/P&gt;
&lt;P&gt;Even though our encryption domain includes the entire subnet in which the VPN cluster's physical and cluster interface sit, clients only get offered the physical interfaces via the encryption domain (confirmed via RA client routing table). For example, I can traceroute to the VPN gateway's physical interfaces fine, but the cluster interface breaks out via the client's local gateway.&lt;/P&gt;
&lt;P&gt;The checkbox to "Exclude gateway's external IP address from VPN domain" is NOT selected. The VPN domain is User defined, but as mentioned includes the entire subnet on which the VPN gateways external interfaces sit.&lt;/P&gt;
&lt;P&gt;Would appreciate any and all ideas on how we can get our RA clients to hit the external IP / SAML portal WHILST connected via VPN.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 07:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253496#M42552</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-07-19T07:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: RA clients not able to access external cluster interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253497#M42553</link>
      <description>&lt;P&gt;So does this ONLY happen when they try to re-authenticate?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 11:12:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253497#M42553</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-19T11:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: RA clients not able to access external cluster interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253499#M42554</link>
      <description>&lt;P&gt;No - I can reproduce this anytime they're connected to the VPN - see my comments regarding the routes on the client.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 11:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253499#M42554</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-07-19T11:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: RA clients not able to access external cluster interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253500#M42555</link>
      <description>&lt;P&gt;Gotcha...let me do some testing in the lab later to check.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 12:05:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253500#M42555</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-19T12:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: RA clients not able to access external cluster interface</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253501#M42556</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9028"&gt;@Ruan_Kotze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just did some tests in my R82 lab, no issues. I have same option about external interface unchecked as you do, I simply made sure external interface IP is included in RA vpn domain, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 19 Jul 2025 13:01:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RA-clients-not-able-to-access-external-cluster-interface/m-p/253501#M42556</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-19T13:01:36Z</dc:date>
    </item>
  </channel>
</rss>

