<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Vpn Location awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/117170#M11815</link>
    <description>&lt;P&gt;Is there any solution to this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 28 Apr 2021 14:08:47 GMT</pubDate>
    <dc:creator>Dominik_L</dc:creator>
    <dc:date>2021-04-28T14:08:47Z</dc:date>
    <item>
      <title>Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/66882#M11811</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have stumbled upon a small issue and we would like your opinion on a possible solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we have a client behind a site 2 site tunnel. The client has Location awareness active and is always building the VPN directly to its VPN gateway, as the connection goes over the external link it is always detected as Outside.&lt;/P&gt;&lt;P&gt;How do we make the Client understand that he is actually internal and should use the Site 2 site tunnel and does not need to build up the client VPN?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The option Domain controller and Network Group is not acceptable, the first does not work as intended and the 2 could lead to other issues, are there any quick solutions for this?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Problem Endpointclient.PNG" style="width: 981px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3010i0B92F541110A6623/image-size/large?v=v2&amp;amp;px=999" role="button" title="Problem Endpointclient.PNG" alt="Problem Endpointclient.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Nov 2019 15:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/66882#M11811</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2019-11-08T15:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/66948#M11812</link>
      <description>Please explain the statements you made in your last paragraph.</description>
      <pubDate>Sat, 09 Nov 2019 08:21:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/66948#M11812</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-09T08:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/67039#M11813</link>
      <description>&lt;P&gt;The option Domain controller and Network Group is not acceptable:&lt;/P&gt;&lt;P&gt;If we enable this it does not work smoothly because the Domain Controller is accessible over the Client VPN.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Explicitly configuring the Network can lead to the situation where at a non trusted location with the same addressing the clients thinks he is internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are investigating if adding the Local networks behind remote site to the encryption domain solves this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 08:09:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/67039#M11813</guid>
      <dc:creator>Ricardo_Gros</dc:creator>
      <dc:date>2019-11-11T08:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/68007#M11814</link>
      <description>Hi , Ricardo,&lt;BR /&gt;how does you solved this issue with the location awareness? We have the same setup, and would be very interested in your solution. Thanks&lt;BR /&gt;Kim</description>
      <pubDate>Thu, 21 Nov 2019 13:03:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/68007#M11814</guid>
      <dc:creator>ksparke</dc:creator>
      <dc:date>2019-11-21T13:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/117170#M11815</link>
      <description>&lt;P&gt;Is there any solution to this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 14:08:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/117170#M11815</guid>
      <dc:creator>Dominik_L</dc:creator>
      <dc:date>2021-04-28T14:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Vpn Location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/141970#M11816</link>
      <description>&lt;P&gt;Ricardo,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I had a similar issue, this is what worked for me.&lt;/P&gt;&lt;P&gt;We created a network group that we called, "Public&amp;nbsp; Networks" and then we created individual networks that would encompass our external public dedicated networks and associated them to the previous group.&lt;/P&gt;&lt;P&gt;Then we configured the network location awareness telling the gateway that every time a user tried connecting from the previously created group they should be consider internal and kicked them out.&lt;/P&gt;&lt;P&gt;This worked as a charm and it was the easiest solution ever.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;@DrVavin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Feb 2022 18:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Vpn-Location-awareness/m-p/141970#M11816</guid>
      <dc:creator>David_Ulloa</dc:creator>
      <dc:date>2022-02-19T18:44:43Z</dc:date>
    </item>
  </channel>
</rss>

