<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access MEP want to add preference to specific gateway. in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-MEP-want-to-add-preference-to-specific-gateway/m-p/82374#M10647</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;This customer has VPN remote users using multiple gateways to connect to company network..&lt;/P&gt;&lt;P&gt;The goal is to have SiteB to handle &amp;gt;80% of the VPN users as the hardware on SiteA is struggling with more than 500 users at a time (constant 85%+ cpu util)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; --------FW_A------&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;BR /&gt;VPN home users --------(WWW)-----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------Company_LAN/WAN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------FW_B--------&lt;/P&gt;&lt;P&gt;FWs are running 80.10 and manager on 80.30&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW_A and FW_B each is has separate Internet breakout with a different provider..&lt;BR /&gt;3k VPN users working from home due to the covid-19 pandemic.&lt;/P&gt;&lt;P&gt;so what cust is finding is using the E80 clients it appears to connect to siteA then will use SiteB when SiteA has reached IP Pool capacity(i suspect) - but always explicitly uses SIteA first.. (SiteB was added recently to handle the growing list of users from home and has a separate Internet breakout to SiteA)&lt;/P&gt;&lt;P&gt;So we have configured MEP loadsharing for now.. will see how that works this week&lt;BR /&gt;This was done as per below and pretty straight forward:&lt;BR /&gt;- amend global config and enable loadsharing on remote access under global proerties on manager&lt;BR /&gt;- Amended the trac_client_1.ttm on the manager and changed mep_mode to 'load_sharing' with (SiteB_IP&amp;amp;#SiteA_IP&amp;amp;#) in the ips_of_gateways_in_mep section.&lt;/P&gt;&lt;P&gt;Result - this appears to do a round robin load balancing on the E80 client connections as expected - will see if this make a difference when the users comes online this week again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;however&lt;/STRONG&gt; what we really want to do is have the users connect to SiteB first and flow over to SiteA when SiteB's ip pool is maxed or load is too high&lt;BR /&gt;FW_A has a /22 and FW_B a /21 vpn ip pool&lt;BR /&gt;The Encr domain on both Sites varies slightly but still both contains 10/8 and 192.168/16 subnets - do they have to be the exact same for both?&lt;/P&gt;&lt;P&gt;Any ideas if this is doable? perhaps some preference that can be set on FW_B perhaps?&lt;BR /&gt;Alternatively another option is to force E80 to connect to FW_B but doesn't seem to be able to do so.. it still defaults to FW_A for some odd reason that i cannot figure out.&lt;BR /&gt;(this works using capsule.. but 90% of users uses the E80 clients)&lt;/P&gt;&lt;P&gt;thanks in adv&lt;/P&gt;</description>
    <pubDate>Sun, 19 Apr 2020 11:11:08 GMT</pubDate>
    <dc:creator>Ants</dc:creator>
    <dc:date>2020-04-19T11:11:08Z</dc:date>
    <item>
      <title>Remote Access MEP want to add preference to specific gateway.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-MEP-want-to-add-preference-to-specific-gateway/m-p/82374#M10647</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;This customer has VPN remote users using multiple gateways to connect to company network..&lt;/P&gt;&lt;P&gt;The goal is to have SiteB to handle &amp;gt;80% of the VPN users as the hardware on SiteA is struggling with more than 500 users at a time (constant 85%+ cpu util)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; --------FW_A------&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |&lt;BR /&gt;VPN home users --------(WWW)-----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------Company_LAN/WAN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------FW_B--------&lt;/P&gt;&lt;P&gt;FWs are running 80.10 and manager on 80.30&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;FW_A and FW_B each is has separate Internet breakout with a different provider..&lt;BR /&gt;3k VPN users working from home due to the covid-19 pandemic.&lt;/P&gt;&lt;P&gt;so what cust is finding is using the E80 clients it appears to connect to siteA then will use SiteB when SiteA has reached IP Pool capacity(i suspect) - but always explicitly uses SIteA first.. (SiteB was added recently to handle the growing list of users from home and has a separate Internet breakout to SiteA)&lt;/P&gt;&lt;P&gt;So we have configured MEP loadsharing for now.. will see how that works this week&lt;BR /&gt;This was done as per below and pretty straight forward:&lt;BR /&gt;- amend global config and enable loadsharing on remote access under global proerties on manager&lt;BR /&gt;- Amended the trac_client_1.ttm on the manager and changed mep_mode to 'load_sharing' with (SiteB_IP&amp;amp;#SiteA_IP&amp;amp;#) in the ips_of_gateways_in_mep section.&lt;/P&gt;&lt;P&gt;Result - this appears to do a round robin load balancing on the E80 client connections as expected - will see if this make a difference when the users comes online this week again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;however&lt;/STRONG&gt; what we really want to do is have the users connect to SiteB first and flow over to SiteA when SiteB's ip pool is maxed or load is too high&lt;BR /&gt;FW_A has a /22 and FW_B a /21 vpn ip pool&lt;BR /&gt;The Encr domain on both Sites varies slightly but still both contains 10/8 and 192.168/16 subnets - do they have to be the exact same for both?&lt;/P&gt;&lt;P&gt;Any ideas if this is doable? perhaps some preference that can be set on FW_B perhaps?&lt;BR /&gt;Alternatively another option is to force E80 to connect to FW_B but doesn't seem to be able to do so.. it still defaults to FW_A for some odd reason that i cannot figure out.&lt;BR /&gt;(this works using capsule.. but 90% of users uses the E80 clients)&lt;/P&gt;&lt;P&gt;thanks in adv&lt;/P&gt;</description>
      <pubDate>Sun, 19 Apr 2020 11:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-MEP-want-to-add-preference-to-specific-gateway/m-p/82374#M10647</guid>
      <dc:creator>Ants</dc:creator>
      <dc:date>2020-04-19T11:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access MEP want to add preference to specific gateway.</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-MEP-want-to-add-preference-to-specific-gateway/m-p/82414#M10648</link>
      <description>MEP requires either both sites to have the exact same encryption domain or one to be a "proper subset" of the other. &lt;BR /&gt;Sounds like the latter might be the case for you.&lt;BR /&gt;In any case, I don't think there's a way to do an 80/20 split but you can set Site_B as the first one.&lt;BR /&gt;See: &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_RemoteAccessVPN_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_RemoteAccessVPN_AdminGuide/html_frameset.htm&lt;/A&gt;</description>
      <pubDate>Mon, 20 Apr 2020 01:18:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-MEP-want-to-add-preference-to-specific-gateway/m-p/82414#M10648</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-20T01:18:59Z</dc:date>
    </item>
  </channel>
</rss>

