<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Initiate from Internal (server) traffic to SSL VPN (RA) users traffic flow - R80.20 in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Initiate-from-Internal-server-traffic-to-SSL-VPN-RA-users/m-p/87587#M10268</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I will keep this as simple as possible.&lt;/P&gt;&lt;P&gt;An internal network segment has a specific host that scan the internal network(s) continuously for any threats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the (new) current scenario the work force are now 100% remote and connects using SSL VPN.&amp;nbsp; Access from the end-user via SSL VPN is not a problem and split-tunnelling is in use.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the order of processing and the way Checkpoint FW's deal with internal traffic to SSL VPN traffic, should I expect that the same 'scanning host' should reach the SSL VPN users if there is any to any policy rule in place for just the scanning host as an object(scanHost_object) and the vpn users (ra_object) as part of a troubleshooting session.&lt;/P&gt;&lt;P&gt;The FW engineers I'm working with could not answer me in terms of whether the Checkpoint would need any 'special' considerations in terms of traffic being initiated from the internal network(s) to RA SSL VPN users.&lt;/P&gt;&lt;P&gt;Any guidance/advise would be appreciated.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Johann&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2020 09:39:12 GMT</pubDate>
    <dc:creator>johannsmith</dc:creator>
    <dc:date>2020-06-08T09:39:12Z</dc:date>
    <item>
      <title>Initiate from Internal (server) traffic to SSL VPN (RA) users traffic flow - R80.20</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Initiate-from-Internal-server-traffic-to-SSL-VPN-RA-users/m-p/87587#M10268</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I will keep this as simple as possible.&lt;/P&gt;&lt;P&gt;An internal network segment has a specific host that scan the internal network(s) continuously for any threats.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the (new) current scenario the work force are now 100% remote and connects using SSL VPN.&amp;nbsp; Access from the end-user via SSL VPN is not a problem and split-tunnelling is in use.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the order of processing and the way Checkpoint FW's deal with internal traffic to SSL VPN traffic, should I expect that the same 'scanning host' should reach the SSL VPN users if there is any to any policy rule in place for just the scanning host as an object(scanHost_object) and the vpn users (ra_object) as part of a troubleshooting session.&lt;/P&gt;&lt;P&gt;The FW engineers I'm working with could not answer me in terms of whether the Checkpoint would need any 'special' considerations in terms of traffic being initiated from the internal network(s) to RA SSL VPN users.&lt;/P&gt;&lt;P&gt;Any guidance/advise would be appreciated.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Johann&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 09:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Initiate-from-Internal-server-traffic-to-SSL-VPN-RA-users/m-p/87587#M10268</guid>
      <dc:creator>johannsmith</dc:creator>
      <dc:date>2020-06-08T09:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Initiate from Internal (server) traffic to SSL VPN (RA) users traffic flow - R80.20</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Initiate-from-Internal-server-traffic-to-SSL-VPN-RA-users/m-p/87990#M10269</link>
      <description>In general, yes, this should work (assuming you're using Office Mode).&lt;BR /&gt;There may be one other setting in Global Properties that needs to be set for this also.</description>
      <pubDate>Thu, 11 Jun 2020 03:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Initiate-from-Internal-server-traffic-to-SSL-VPN-RA-users/m-p/87990#M10269</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-11T03:16:39Z</dc:date>
    </item>
  </channel>
</rss>

