<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL-VPN fails during HA Failover in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81858#M10709</link>
    <description>Is your goal to always use the Comcast address for Remote Access termination?</description>
    <pubDate>Tue, 14 Apr 2020 21:10:09 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-04-14T21:10:09Z</dc:date>
    <item>
      <title>SSL-VPN fails during HA Failover</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81699#M10708</link>
      <description>&lt;P&gt;&lt;EM&gt;Topology:&amp;nbsp; (2) CP 5600 2 R80.30 in active/standby HA w/ ISP-Redunancy load-balancing&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VPN client: Checkpoint Mobile for Windows&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Here is the problem:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shutdown the Comcast fiber ISP connection. This is NOT the firewall interfaces but the switch port to the Comcast fiber. So the firewall ComCast fiber interfaces stay up. The Comcast fiber ISP side is down.&lt;/P&gt;&lt;P&gt;Create a VPN client connection to the DR Comcast coax connection (173.162.x.x).&lt;/P&gt;&lt;P&gt;Connect to the DR connection – everything AOK. Properties of connection show name and IP address are 173.162.x.x.&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Disconnect from DR connection&lt;/P&gt;&lt;P&gt;Reconnect to DR connection. Connection details are updated to include Comcast Fiber IP address.&lt;/P&gt;&lt;P&gt;I think this problem is due to the firewalls serving up the main IP as the VPN gateway.&lt;/P&gt;&lt;P&gt;Any suggestions on how to resolve this?&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Apr 2020 15:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81699#M10708</guid>
      <dc:creator>vlw38</dc:creator>
      <dc:date>2020-04-13T15:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-VPN fails during HA Failover</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81858#M10709</link>
      <description>Is your goal to always use the Comcast address for Remote Access termination?</description>
      <pubDate>Tue, 14 Apr 2020 21:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81858#M10709</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-14T21:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-VPN fails during HA Failover</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81955#M10710</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes we want to always use the Comcast address but, we have two Comcast links – Comcast fiber/ISP#1 and Comcast Coax/ISP#2. We have ISP Redundancy enabled. &amp;nbsp;In Gateway Cluster Properties/IPSEC VPN/LinkSelection we have Comcast fiber/ISP#1 = Always Use This IP Address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The&amp;nbsp;Use Probing /Link Redundancy Mode offers the option to include both the Comcast fiber/ISP#1 and Comcast Coax/ISP#2 ip addresses. We spoke w/CP and they told us that none of the remote clients support/recognize the Probing config as per SK113617. They offered options such as manual failover (type in Comcast Coax/ISP#2 in Gateway Cluster Properties/IPSEC VPN/LinkSelection)&amp;nbsp; or installing another fw an using some type of MEP config. Ridiculous!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 12:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/81955#M10710</guid>
      <dc:creator>vlw38</dc:creator>
      <dc:date>2020-04-15T12:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-VPN fails during HA Failover</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/82007#M10711</link>
      <description>&lt;P&gt;Dear vlw38,&lt;/P&gt;
&lt;P&gt;this is normal behaviour for VPN client connections. Link selection configuration via SmartConsole is used only for site 2 site VPN.&lt;/P&gt;
&lt;P&gt;You have to follow &amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32229" target="_blank" rel="noopener"&gt;Configuring VPN Link Selection for Remote Access client&lt;/A&gt;&amp;nbsp;to configure.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92383" target="_blank" rel="noopener"&gt;Remote Access clients can connect to VPN Gateway only once&lt;/A&gt;&amp;nbsp;shows your problem.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 16:13:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/82007#M10711</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-04-15T16:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL-VPN fails during HA Failover</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/82056#M10712</link>
      <description>&lt;P&gt;Thank you for the information.&amp;nbsp; We will test the configs referenced in your provided&amp;nbsp;links&amp;nbsp;in the next 5 days.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 23:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SSL-VPN-fails-during-HA-Failover/m-p/82056#M10712</guid>
      <dc:creator>vlw38</dc:creator>
      <dc:date>2020-04-15T23:40:21Z</dc:date>
    </item>
  </channel>
</rss>

