<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN multiple pools and IP assignment in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93151#M10057</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually have a R80.20 cluster with 2 gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All employees are allowed to have a remote access using&amp;nbsp; Checkpoint Mobile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they do so, they get a 172.16.10.0/23 address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First problem :&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to allocate few IP addresses in this range. I did it by modifying the ipassignment.conf file .&lt;/P&gt;&lt;P&gt;In the beginning it was working fine.&amp;nbsp;But, I then realized the IP address was given to another employee who has connected earlier in the day...how is it possible to overwrite the reservation like that ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second problem :&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decide to allocate static IP address for the concerned users in another subnet (let's say 10.x.x.x/24), so that I'm not bothered by the first problem.&lt;/P&gt;&lt;P&gt;The problem is, as soon I'm connected by VPN with the new IP address I set, I get disconnected 30 seconds later .&lt;/P&gt;&lt;P&gt;In the logs, I can see that my traffic&amp;nbsp; links with the external interfaces but all the packets get dropped with "Address spoofing" error message. In fact, my traffic isn't listed as "VPN" feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How could I fixe one or both problems ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 10:42:06 GMT</pubDate>
    <dc:creator>Cisco59</dc:creator>
    <dc:date>2020-08-03T10:42:06Z</dc:date>
    <item>
      <title>Remote Access VPN multiple pools and IP assignment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93151#M10057</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I actually have a R80.20 cluster with 2 gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All employees are allowed to have a remote access using&amp;nbsp; Checkpoint Mobile.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When they do so, they get a 172.16.10.0/23 address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First problem :&amp;nbsp;&lt;/P&gt;&lt;P&gt;I wanted to allocate few IP addresses in this range. I did it by modifying the ipassignment.conf file .&lt;/P&gt;&lt;P&gt;In the beginning it was working fine.&amp;nbsp;But, I then realized the IP address was given to another employee who has connected earlier in the day...how is it possible to overwrite the reservation like that ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second problem :&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decide to allocate static IP address for the concerned users in another subnet (let's say 10.x.x.x/24), so that I'm not bothered by the first problem.&lt;/P&gt;&lt;P&gt;The problem is, as soon I'm connected by VPN with the new IP address I set, I get disconnected 30 seconds later .&lt;/P&gt;&lt;P&gt;In the logs, I can see that my traffic&amp;nbsp; links with the external interfaces but all the packets get dropped with "Address spoofing" error message. In fact, my traffic isn't listed as "VPN" feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How could I fixe one or both problems ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 10:42:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93151#M10057</guid>
      <dc:creator>Cisco59</dc:creator>
      <dc:date>2020-08-03T10:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN multiple pools and IP assignment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93348#M10058</link>
      <description>&lt;P&gt;If you want to assign a specific user a specific IP, it cannot be in your general Office Mode range, at least as I understand it.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2020 03:20:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93348#M10058</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-05T03:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN multiple pools and IP assignment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93636#M10059</link>
      <description>&lt;P&gt;First problem:&lt;/P&gt;&lt;P&gt;Networks in ipassignment.conf must be different than the Office mode network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second problem:&lt;/P&gt;&lt;P&gt;You have to add the network that you give for VPN users in the SmartConsole-&amp;gt;GW options-&amp;gt;Network Management-&amp;gt;your external interface, facing VPN users-&amp;gt;Modify topology-&amp;gt;Don't check packets from, or just disable anti-spoofing on the external interface (not so secure).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 12:26:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-multiple-pools-and-IP-assignment/m-p/93636#M10059</guid>
      <dc:creator>MartinTzvetanov</dc:creator>
      <dc:date>2020-08-07T12:26:10Z</dc:date>
    </item>
  </channel>
</rss>

