<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN not working from public network in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275418#M45995</link>
    <description>&lt;P&gt;I solved this problem but I posted this question that I don't get any response.&lt;BR /&gt;Could you please give me more information about this: is it possible to assign a separate IP address for the Site-to-Site IPsec tunnel instead of using the VIP address, in order to separate it from other VPN services? This address must be subject of device failover, not only physical interface address.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2026 12:48:42 GMT</pubDate>
    <dc:creator>paki</dc:creator>
    <dc:date>2026-04-14T12:48:42Z</dc:date>
    <item>
      <title>Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275185#M45962</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I am reaching out regarding an issue with Remote Access VPN connectivity and I would appreciate any insights.&lt;/P&gt;&lt;P&gt;When I try to create a new site connection using the Endpoint Security VPN client from a public network (such as home WiFi or mobile internet), the connection fails with the error: “Site creation failed. Failed to create the new site. Site is not responding.”&lt;/P&gt;&lt;P&gt;However, when I perform the same test from a DMZ network, the VPN connection works without any issues. I am able to connect successfully using the VIP IP address and everything functions as expected. Additionally, the Site-to-Site VPN tunnel is up and running correctly on the same interface (that is VIP IP).&lt;/P&gt;&lt;P&gt;In terms of configuration, I have two gateways configured in a ClusterXL setup and the VIP address is used for VPN communication (Remote access for clients and Site2Site VPN). Now, I am on product version Check Point Gaia R81.20.&lt;/P&gt;&lt;P&gt;My questions are the following:&lt;BR /&gt;what could be the reasons why Remote Access VPN does not work from a public network, while it works from internal or DMZ networks?&lt;/P&gt;&lt;P&gt;Also, is it possible to assign a separate IP address for the Site-to-Site IPsec tunnel instead of using the VIP address, in order to separate it from other VPN services?&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 12:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275185#M45962</guid>
      <dc:creator>paki</dc:creator>
      <dc:date>2026-04-09T12:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275209#M45965</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;could you try to share any screenshot you can about the VPN configuration?&lt;/P&gt;
&lt;P&gt;Did you try to catpure traffic on external interface of the firewall, to see if your traffic for site creation is arriving?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 14:56:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275209#M45965</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-09T14:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275225#M45966</link>
      <description>&lt;P&gt;Check out these settings. Second screenshot have impact also for normal site to site tunnels!&lt;/P&gt;
&lt;P&gt;Second check traffic logs if https port is allowed. This is needed to setup the client VPN.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 549px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33986i01BF17FFCEB52C21/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 686px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33987iB259E3B07EB88C84/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 18:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275225#M45966</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-04-09T18:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275396#M45991</link>
      <description>&lt;P&gt;Thank you for your suggestion.&lt;/P&gt;&lt;P&gt;I have already reviewed and applied these settings and the current setup matches what you described. I also checked the traffic logs and verified that ports (UDP 500, UDP 4500, HTTPS 443) are allowed.&lt;/P&gt;&lt;P&gt;If possible could you please share a screenshot from the Network Management / Topology section (interfaces view)?&lt;BR /&gt;I would like to compare the interface configuration and topology settings to see if there are any differences that might explain the issue.&lt;/P&gt;&lt;P&gt;I have also created a simple diagram to illustrate my setup:&lt;BR /&gt;My side is a Check Point ClusterXL using a VIP address for VPN communication&lt;BR /&gt;Remote Access clients connect through the same VIP&lt;BR /&gt;There is also a Site-to-Site VPN tunnel to a 3rd-party (non-Check Point) device&lt;BR /&gt;Both Remote Access and Site-to-Site are working internally, but Remote Access fails from public networks.&lt;/P&gt;&lt;P&gt;Do you think this setup looks correct or is there something obvious I might be missing?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 07:34:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275396#M45991</guid>
      <dc:creator>paki</dc:creator>
      <dc:date>2026-04-14T07:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275403#M45994</link>
      <description>&lt;P&gt;I would like to inform you that the issue has been resolved.&lt;/P&gt;&lt;P&gt;The problem was related to the Link Selection configuration. In IPsec VPN &amp;gt; Link Selection, I changed the setting from “Selected address from topology table” to “Statically NATed IP” and specified peer address.&lt;/P&gt;&lt;P&gt;After this change, Remote Access VPN works from public networks and the Site-to-Site VPN is also functioning correctly.&lt;/P&gt;&lt;P&gt;Thank you all for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 08:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275403#M45994</guid>
      <dc:creator>paki</dc:creator>
      <dc:date>2026-04-14T08:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275418#M45995</link>
      <description>&lt;P&gt;I solved this problem but I posted this question that I don't get any response.&lt;BR /&gt;Could you please give me more information about this: is it possible to assign a separate IP address for the Site-to-Site IPsec tunnel instead of using the VIP address, in order to separate it from other VPN services? This address must be subject of device failover, not only physical interface address.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 12:48:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275418#M45995</guid>
      <dc:creator>paki</dc:creator>
      <dc:date>2026-04-14T12:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275419#M45996</link>
      <description>&lt;P&gt;For what I know, you can only use IP addresses (VIP) configured on the firewall ... so the right answer is no you can't, unless you have two differente Internet connections .. and in any case it add complexity in my opinion; if you have only one internet connection there is no real reason and advantage to separate vpn service (and as I told you, is not possible).&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 12:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275419#M45996</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-14T12:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN not working from public network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275421#M45997</link>
      <description>&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;Everything is working fine now. I just wanted to ask for clarification for future reference in case I need to introduce additional services or make changes to the setup later.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 13:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-not-working-from-public-network/m-p/275421#M45997</guid>
      <dc:creator>paki</dc:creator>
      <dc:date>2026-04-14T13:07:58Z</dc:date>
    </item>
  </channel>
</rss>

