<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN in a Load-sharing Cluster Environment in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28956#M5924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Make sure that it is routed into and out of your internal cluster and networks and is included in the security policy applied to your internal cluster"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Could you elaborate on this.? Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Sep 2018 16:10:46 GMT</pubDate>
    <dc:creator>Di_Junior</dc:creator>
    <dc:date>2018-09-24T16:10:46Z</dc:date>
    <item>
      <title>Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28948#M5916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Mates&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are doing fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I started working as Check Point admin of a large corporation, and my first challenge is to migrate our Remote Access VPN from one vendor that we are currently using to Check Point Remote Access VPN solution. I have implemented Remote Access VPNs in simple environments with a single gateway and Management server, but I now have to implement it in a much complex environment, thats why I need a hand.&amp;nbsp;The diagram bellow gives an high-level overview of our infrastructure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70829_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the diagram above, I would like to have your help with regards to the following questions:&lt;/P&gt;&lt;P&gt;1. Do I have to buy remote access VPN (mobile access) for both clusters (Internal and external)? if yes why? if not why?&lt;/P&gt;&lt;P&gt;2. Since the clusters are operating in Load-sharing unicast, do I have to activate Sticky Decision Function in cluster properties? if yes why? if no why?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. Should Sticky Decision Function be activated on both clusters (Internal and External)?&lt;SPAN&gt;if yes why? if no why?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4. Is there any documentation or SK you would recommend for implementation of Remote Access VPN in similar environment? or maybe share your experience if you have worked on similar environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2018 12:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28948#M5916</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-23T12:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28949#M5917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need the Mobile Access licenses only for the cluster on which RA VPN connections will be terminated.&lt;/P&gt;&lt;P&gt;If your External cluster is in a full routing mode, then that the one that will need mobile access licenses.&lt;/P&gt;&lt;P&gt;If your External cluster is in the transparent bridge mode, you'll have to use licenses on the Internal cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your clusters are indeed consist of two simple gateways, there is no benefit from load sharing being enabled, just complications. I.e. you are still limited to the 50% capacity on each cluster member, otherwise, if one of the members will fail, the other will be overloaded.&lt;/P&gt;&lt;P&gt;Load sharing makes sense if: 1. you have 3+ gateways, 2. you are planning to expand the existing cluster in a foreseeable future.&lt;/P&gt;&lt;P&gt;I seldom see the #2, as once cluster deployed, the hardware tend to go towards obsolescence relatively fast and it is hard to justify buying identical units down the road. This may be different with scalable platforms, but I have no experience working with those.&lt;/P&gt;&lt;P&gt;If you are planning to use SSL Network Extender, you'l have to use Sticky Decisions, see &lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/23007" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/23007"&gt;Mobile Access R80.10 Administration Guide&lt;/A&gt;&amp;nbsp; and search for "cluster".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2018 13:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28949#M5917</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-23T13:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28950#M5918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. You needed to buy Mobile Access licenses only for the cluster that will provide this functionality, ideally this would be your external cluster.&lt;/P&gt;&lt;P&gt;2. Mobile Access in Load Sharing Clusters automatically enables SDF (Sticky mode), which disables SecureXL &amp;gt; Read:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101539"&gt;ClusterXL Load Sharing mode limitations and important notes&lt;/A&gt; and &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65486" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65486"&gt;Which features are not supported when the Sticky Decision Function (SDF) is enabled in ClusterXL object?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3. See 2. It will be automatically enabled on the MOB cluster. You don't need to enable it on the other one.&lt;/P&gt;&lt;P&gt;4. You have a much bigger issue mate. Clusters with less than three or more than four cluster members are not recommended for Load Sharing mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2018 16:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28950#M5918</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-23T16:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28951#M5919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the great inputs you shared., it will definetely be very helpful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2018 17:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28951#M5919</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-23T17:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28952#M5920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your contribution &lt;A href="https://community.checkpoint.com/migration-blogpost/1139"&gt;Danny Yang 的部落格&lt;/A&gt;. it will be very helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please share the link you wanted to share in point 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Sep 2018 17:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28952#M5920</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-23T17:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28953#M5921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have managed to get the Remote Access VPN working with the licences on the external cluster, but I am facing a little challenge. The remote clients are only able to communicate with the operation &amp;amp; Management interfaces of the Gateways and Management, not the rest of the network. In the Destination side of the access rule I am using "Any" which means I should be able to reach any network behind the gateway (which is not happening): Any hints on how I could overcome this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 14:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28953#M5921</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-24T14:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28954#M5922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check what you have defined in your Encryption Domain and your Encryption Domain for Remote Access as well as what is defined in the topology of your gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally, you may be NATting the outbound traffic behind external IP of your internal cluster.&lt;/P&gt;&lt;P&gt;If this is the case, you should stop doing that and route networks to the external cluster unchanged, leaving NAT duties to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the routing from external cluster to internal network before troubleshooting VPN.&lt;/P&gt;&lt;P&gt;Your Remote Clients are likely getting IPs assigned from the "CP_default_Office_Mode_addresses_pool" network object on the external cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that it is routed into and out of your internal cluster and networks and is included in the security policy applied to your internal cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 15:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28954#M5922</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-24T15:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28955#M5923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladmir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your prompt reply and help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed the office-mode pool address to an address that will not have conflict in our internal network.&lt;/P&gt;&lt;P&gt;I changed the Encryption Domain, and now I get routes to all the operations and Magement IP addresses. Thanks for your help.&lt;/P&gt;&lt;P&gt;I can ping the internal hosts through their O&amp;amp;M interfaces and I get replies successfully. But when I try to RDP an internal server, the connection goes to the Clean-up rule. (see bellow image)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70859_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts as to how this could be overcomed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your great comments.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 16:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28955#M5923</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-24T16:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28956#M5924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Make sure that it is routed into and out of your internal cluster and networks and is included in the security policy applied to your internal cluster"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Could you elaborate on this.? Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 16:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28956#M5924</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-24T16:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28957#M5925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, besides the obvious, "Have you created the rule permitting RDP from this source to this destination", the "Information field in the event you are showing contains:&lt;/P&gt;&lt;P&gt;Inzone: External&lt;/P&gt;&lt;P&gt;Outzone: External&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the topology and verify that the Pool's IP is included in the Internal cluster's "External" manually defined group. That there is a route in Gaia configs of both members pointing Pool's network to your External cluster's vIP and your internal networks are define behind Internal interfaces topology in both, external and Internal clusters objects.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 16:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28957#M5925</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-24T16:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28958#M5926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your internal GWs should know that the Pool's range is on its external interface.&lt;/P&gt;&lt;P&gt;Your security policy should permit communication between Pool's range and your internal hosts that you are trying to connect to.&lt;/P&gt;&lt;P&gt;Your External Cluster's Internal interface topology should contain the same networks that are defined behind your Internal Cluster's Internal interface (in addition to intermediate network between internal and external clusters), else they will be treated as spoofed.&lt;/P&gt;&lt;P&gt;While you do have route 0 on your internal cluster members that should route your internal hosts to the Pool's range, I'd personally feel better adding explicit route for the Pool, pointing to the External Cluster's internal vIP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2018 16:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28958#M5926</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-24T16:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28959#M5927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@&lt;A _jive_internal="true" class="" data-avatarid="1600" data-externalid="" data-online="false" data-presence="null" data-userid="48025" data-username="vladff097c1d-a31f-483e-9404-5bf20903d568" href="https://community.checkpoint.com/people/vladff097c1d-a31f-483e-9404-5bf20903d568" style="color: inherit; background-color: #ffffff; border: 0px; font-weight: bold; text-decoration: underline; font-size: 14px;"&gt;Vladimir Yakovlev&lt;/A&gt;&amp;nbsp;I would like to thank you for all your inputs during this migration process. Thanks to your contribution I got everthing up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On behalf of my company, I thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 10:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28959#M5927</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T10:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28960#M5928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are quite w:)lcome!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28960#M5928</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-28T12:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28961#M5929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have one more question for you before closing this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont want our partners to connect to our VPN and get the message that the certificate is not trusted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you kindly recommend which type of certificate has to be paid in order to overcome this situation? Since we have two different sites, do we have to buy two certificates or one should suffice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again, thank you again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 13:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28961#M5929</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T13:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28962#M5930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any trusted CA cert would work.&lt;/P&gt;&lt;P&gt;GoDady is now the cheapest and most common source for the certs.&lt;/P&gt;&lt;P&gt;Please follow this post by &lt;A href="https://community.checkpoint.com/migrated-users/46233" target="_blank"&gt;Gaurav Pandya&lt;/A&gt;‌ to issue a CSR for the upload to the CA and the installation of the certificate:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2732-create-csr-and-importing-third-part-certificate-in-mobile-access-blade" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-2732-create-csr-and-importing-third-part-certificate-in-mobile-access-blade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:15:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28962#M5930</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-06-21T09:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28963#M5931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 13:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28963#M5931</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T13:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28964#M5932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If it is not too much trouble, please leave a brief feedback on my LinkedIn page:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.linkedin.com/in/vladimiry/" title="https://www.linkedin.com/in/vladimiry/"&gt;https://www.linkedin.com/in/vladimiry/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are ramping-up our services and&amp;nbsp;all positive references are appreciated.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 17:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28964#M5932</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-28T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28965#M5933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why or why people are still using Load Sharing mode?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 17:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28965#M5933</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-28T17:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28966#M5934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not a trouble at all. Please accept my request so that I can recommend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jivelink1" href="https://www.linkedin.com/in/dialungana-malungo-50321998/" title="https://www.linkedin.com/in/dialungana-malungo-50321998/"&gt;https://www.linkedin.com/in/dialungana-malungo-50321998/&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 17:11:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28966#M5934</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T17:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN in a Load-sharing Cluster Environment</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28967#M5935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi @&lt;A _jive_internal="true" class="" data-avatarid="2183" data-externalid="" data-online="false" data-presence="null" data-userid="2138" data-username="vlouk80ce7dc1-40a3-44d6-a227-b5782636a5cb" href="https://community.checkpoint.com/people/vlouk80ce7dc1-40a3-44d6-a227-b5782636a5cb" style="color: inherit; background-color: #ffffff; border: 0px; font-weight: bold; text-decoration: underline; font-size: 14px;"&gt;Valeri Loukine&lt;/A&gt;&amp;nbsp;I just took over as the Check Point Administrator in the company. And ny good recommendation that I can get is welcomed. I hold a CCSE certification but I do not have much experience as this is my first job as the CP admin. Is there any documentation that you would suggest which can give more information as to why Load sharing should not be used.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 17:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-in-a-Load-sharing-Cluster-Environment/m-p/28967#M5935</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2018-09-28T17:14:42Z</dc:date>
    </item>
  </channel>
</rss>

