<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traffic initiated from Lan to VPN Endpoint Client Blocked in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255685#M43004</link>
    <description>&lt;P&gt;Can you attach full log please? Also, maybe worth trying E89 client version as a test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 21 Aug 2025 19:36:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-08-21T19:36:28Z</dc:date>
    <item>
      <title>Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255659#M42993</link>
      <description>&lt;P&gt;Recently migrated from a Cisco ASA to a CP3800 R82.&amp;nbsp;&amp;nbsp; With the Cisco we were able to reach the VPN clients with traffic initiated from the Lan.&amp;nbsp;&amp;nbsp; This isn't happening with the CP.&amp;nbsp; Logs show Lan initiated traffic being encrypted on the gateway, but that is where it ends.&amp;nbsp; I don't have a NAT setup at this time between the VPN subnet and Lan.&amp;nbsp; Not sure if that is the missing piece or it's something else.&lt;/P&gt;&lt;P&gt;Policy rules:&lt;/P&gt;&lt;P&gt;1. source: &lt;A href="mailto:vpn@any," target="_blank"&gt;vpn@any,&lt;/A&gt; dest: intLan, VPN: RemoteAccess, Serv&amp;amp;app: Any, Action: Accept&lt;BR /&gt;2. source: intLan, dest: Any, VPN: Any, Serv&amp;amp;app: Any, Action: Accept&lt;BR /&gt;3. source: VPNsubnet, dest: intLan, VPN: Any, Serv&amp;amp;app: Any, Action: Accept&lt;BR /&gt;4. Cleanup rule&lt;/P&gt;&lt;P&gt;Added Rule #3 but didn't make a difference.&lt;BR /&gt;&lt;BR /&gt;If the Endpoint Client only applies policy assigned to the VPN community (RemoteAccess), then that would explain what is happening.&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 14:49:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255659#M42993</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-21T14:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255672#M42996</link>
      <description>&lt;P&gt;By default, this is blocked in Global Properties.&lt;BR /&gt;Enable Back Connections and push policy.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31278i7CB0668542D5512C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 16:58:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255672#M42996</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-08-21T16:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255673#M42997</link>
      <description>&lt;P&gt;That is currently enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 17:27:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255673#M42997</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-21T17:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255675#M42998</link>
      <description>&lt;P&gt;Just to make sure Im not missing anything...are you saying when people connect with VPN client, they cant access anything behind the fw?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 18:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255675#M42998</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T18:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255676#M42999</link>
      <description>&lt;P&gt;Now that I re-read your post, I believe NAT could be the issue. Make sure vpnsubnet object is natted in smart console, just do behind gateway.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 18:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255676#M42999</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T18:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255677#M43000</link>
      <description>&lt;P&gt;VPN clients when connected, can access anything just fine on the network, without a NAT.&amp;nbsp;&amp;nbsp; It's when for example my PC on the Lan tries to connect to a VPN client, that it does not work.&amp;nbsp;&amp;nbsp; Ping, remote desktop, anything....does not work.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 18:23:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255677#M43000</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-21T18:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255678#M43001</link>
      <description>&lt;P&gt;Ah, got it now...so can you do this when trying on the fw (or if its cluster, whichever is active atm)&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep x.x.x.x&lt;/P&gt;
&lt;P&gt;Just replace x.x.x.x with IP you are trying to connect to&lt;/P&gt;
&lt;P&gt;ctrl+c to stop&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 18:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255678#M43001</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T18:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255683#M43002</link>
      <description>&lt;P&gt;Nothing showed up in dubug on the cluster.&amp;nbsp;&amp;nbsp;&amp;nbsp; Attached log showing traffic being encrypted to the vpn client.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked trac logs on the client, nothing with my source IP in it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp-enc.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31279i6A7C1AE0803C7B05/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp-enc.jpg" alt="cp-enc.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 19:28:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255683#M43002</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-21T19:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255684#M43003</link>
      <description>&lt;P&gt;Client is E88.30&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 19:31:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255684#M43003</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-21T19:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255685#M43004</link>
      <description>&lt;P&gt;Can you attach full log please? Also, maybe worth trying E89 client version as a test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 19:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255685#M43004</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T19:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255687#M43006</link>
      <description>&lt;P&gt;Now that I think about it, lets start with basics, as they say.&lt;/P&gt;
&lt;P&gt;1) what subnet is assigned for vpn clients?&lt;/P&gt;
&lt;P&gt;2) when connection fails to connect back from lan, what do you see when running route print from your machine?&lt;/P&gt;
&lt;P&gt;3) If you run ip r g and then IP of the vpn client, does it show correct info? ie : ip r g 10.10.10.50&lt;/P&gt;
&lt;P&gt;4) if no drops are observed, then we can say with high confidence that rules are fine, but to be 100% sure, you can run example 1 from below link on the fw itself, just add dst IP as well, ipp can be 0&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 19:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255687#M43006</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-21T19:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255746#M43016</link>
      <description>&lt;P&gt;Logs attached.&lt;/P&gt;&lt;P&gt;Tried E89 and no change.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 12:50:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255746#M43016</guid>
      <dc:creator>jb8578</dc:creator>
      <dc:date>2025-08-22T12:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic initiated from Lan to VPN Endpoint Client Blocked</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255751#M43021</link>
      <description>&lt;P&gt;I meant smart console log.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 13:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-initiated-from-Lan-to-VPN-Endpoint-Client-Blocked/m-p/255751#M43021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-08-22T13:39:34Z</dc:date>
    </item>
  </channel>
</rss>

