<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access on separate external interface in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78467#M11250</link>
    <description>Hi Chris, thanks for the reply.&lt;BR /&gt;We do have the 'Support connectivity enhancement for gateways with multiple external interfaces' option checked but the issue still remains.&lt;BR /&gt;Could you elaborate a little on how I could handle this with an external router?&lt;BR /&gt;The use case is quite simple, we want the 'Mobile Access' tunneled traffic to be on the second ISP link, to liberate some bandwidth on the main ISP connection where we're already at maximum capacity. There wouldn't be anything other than that VPN traffic on that link.&lt;BR /&gt;</description>
    <pubDate>Mon, 16 Mar 2020 17:42:49 GMT</pubDate>
    <dc:creator>Remi_Richer</dc:creator>
    <dc:date>2020-03-16T17:42:49Z</dc:date>
    <item>
      <title>Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78238#M11248</link>
      <description>&lt;P&gt;Hello Checkmates,&lt;/P&gt;&lt;P&gt;I need some help with a new VPN setup we're trying to implement. I need to be using a second external interface leading to a second distinct ISP (eth1). We're trying to set Mobile Access on that interface for bandwidth reasons. My issue currently is that when we try to reach the portal, traffic comes in on eth1 but the http responses are going outbound on the other external interface/ISP (eth4) because of the default route and makes it impossible to access remotely (the portal works fine when accessing from internal networks).&lt;BR /&gt;&lt;BR /&gt;Is there a way to get around this? So far I've looked at the documentation on ISP-Redundancy which doesn't seem to apply at all for my scenario. I also looked into Policy-Based-Routing but couldn't make it work; I think it's just not meant for what I'm trying to do, unless I'm implementing it wrong.&lt;/P&gt;&lt;P&gt;Any help is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 18:10:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78238#M11248</guid>
      <dc:creator>Remi_Richer</dc:creator>
      <dc:date>2020-03-13T18:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78293#M11249</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;Do you have the&amp;nbsp;&lt;STRONG class="bold"&gt;Support connectivity enhancement for gateways with multiple external interfaces&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;option set?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;VSX may also be an option depending on your intended use cases for the second ISP link.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Another would be to implement an external router for handling that element.&lt;/P&gt;</description>
      <pubDate>Sat, 14 Mar 2020 12:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78293#M11249</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-03-14T12:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78467#M11250</link>
      <description>Hi Chris, thanks for the reply.&lt;BR /&gt;We do have the 'Support connectivity enhancement for gateways with multiple external interfaces' option checked but the issue still remains.&lt;BR /&gt;Could you elaborate a little on how I could handle this with an external router?&lt;BR /&gt;The use case is quite simple, we want the 'Mobile Access' tunneled traffic to be on the second ISP link, to liberate some bandwidth on the main ISP connection where we're already at maximum capacity. There wouldn't be anything other than that VPN traffic on that link.&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Mar 2020 17:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78467#M11250</guid>
      <dc:creator>Remi_Richer</dc:creator>
      <dc:date>2020-03-16T17:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78506#M11251</link>
      <description>&lt;P&gt;I'm guessing this is how to solve the issue.&lt;BR /&gt;In the Gateway Object, go to IPSec VPN &amp;gt; Link Selection, hit the Setup button under Outgoing Route Selection and select Reply from Same Interface.&lt;BR /&gt;Install policy.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-03-16 at 6.40.12 PM.png" style="width: 919px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4858i2C74EF9F61443977/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-03-16 at 6.40.12 PM.png" alt="Screen Shot 2020-03-16 at 6.40.12 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 01:42:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78506#M11251</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-17T01:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78532#M11252</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm having the exact same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried your suggestion, but did not worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I thing is important to mention sk in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32229&amp;amp;partition=Basic&amp;amp;product=Endpoint" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32229&amp;amp;partition=Basic&amp;amp;product=Endpoint&lt;/A&gt;. Also tried that, but no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anymore ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;César Sant&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Mar 2020 11:42:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78532#M11252</guid>
      <dc:creator>Cesar_Santos</dc:creator>
      <dc:date>2020-03-17T11:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access on separate external interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78703#M11253</link>
      <description>That didn't work for me, unfortunately. We are using the SSL network Extender currently so I don't think IPSec Link Selection impacts anything here. Maybe that could work with one of the VPN clients (so far I tried 'Endpoint Security VPN' but it's the same issue, it couldn't even create the site; 'site is not responding). We'll probably deploy a 2200 gateway we have lying around and handle this ISP separately with it. I can't find any built-in settings to make this work otherwise.</description>
      <pubDate>Wed, 18 Mar 2020 15:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-on-separate-external-interface/m-p/78703#M11253</guid>
      <dc:creator>Remi_Richer</dc:creator>
      <dc:date>2020-03-18T15:33:24Z</dc:date>
    </item>
  </channel>
</rss>

