<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sometimes unencrypted traffic to the remote access clients in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Sometimes-unencrypted-traffic-to-the-remote-access-clients/m-p/82107#M10656</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have an issue with our remote access employees.&lt;/P&gt;&lt;P&gt;We have employees with softphones, who connect to our phone server through Check Point Endpoint Security VPN.&lt;/P&gt;&lt;P&gt;I made two access rules, one for SIP traffic from RA Clients to the phone server and one for RTP (UDP/20000-25000) traffic from the server to the Remote Access Net.&lt;/P&gt;&lt;P&gt;Also, we have iBGP from the internal side, so I made a route on VS gateway (we have VSX) to the Remote Access Net, with the external gateway as a next-hop (to announce RA Net to BGP).&lt;/P&gt;&lt;P&gt;Everything works fine. But 3-4 times a day some employees don't hear a caller. I looked through logs and found out, that in such cases RTP packets don't go to the client but unencrypted go to the Internet.&lt;/P&gt;&lt;P&gt;What can be the problem? How to debug the issue?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 11:04:20 GMT</pubDate>
    <dc:creator>AntonMakarychev</dc:creator>
    <dc:date>2020-04-16T11:04:20Z</dc:date>
    <item>
      <title>Sometimes unencrypted traffic to the remote access clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Sometimes-unencrypted-traffic-to-the-remote-access-clients/m-p/82107#M10656</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I have an issue with our remote access employees.&lt;/P&gt;&lt;P&gt;We have employees with softphones, who connect to our phone server through Check Point Endpoint Security VPN.&lt;/P&gt;&lt;P&gt;I made two access rules, one for SIP traffic from RA Clients to the phone server and one for RTP (UDP/20000-25000) traffic from the server to the Remote Access Net.&lt;/P&gt;&lt;P&gt;Also, we have iBGP from the internal side, so I made a route on VS gateway (we have VSX) to the Remote Access Net, with the external gateway as a next-hop (to announce RA Net to BGP).&lt;/P&gt;&lt;P&gt;Everything works fine. But 3-4 times a day some employees don't hear a caller. I looked through logs and found out, that in such cases RTP packets don't go to the client but unencrypted go to the Internet.&lt;/P&gt;&lt;P&gt;What can be the problem? How to debug the issue?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 11:04:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Sometimes-unencrypted-traffic-to-the-remote-access-clients/m-p/82107#M10656</guid>
      <dc:creator>AntonMakarychev</dc:creator>
      <dc:date>2020-04-16T11:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes unencrypted traffic to the remote access clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Sometimes-unencrypted-traffic-to-the-remote-access-clients/m-p/82122#M10657</link>
      <description>You're most likely in TAC ticket territory here, particularly if the same client had been receiving the RTP traffic encrypted before then it suddenly stopped working.&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Apr 2020 13:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Sometimes-unencrypted-traffic-to-the-remote-access-clients/m-p/82122#M10657</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-16T13:54:03Z</dc:date>
    </item>
  </channel>
</rss>

