<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MAB - Route Traffic via Gateway in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66218#M11821</link>
    <description>&lt;P&gt;We use the Mobile Access Blade for connecting into our systems and we also use a PACFILE for internet access.&lt;/P&gt;&lt;P&gt;Once a user has connected onto the MAB, if they untick the PACFILE on IE, then they can get to websites that would be blocked.&lt;/P&gt;&lt;P&gt;Ie - PACFILE would stop access to File Sharing sites, but a user can uncheck the PACFILE and then access File Sharing sites whilst still connected to the MAB.&lt;/P&gt;&lt;P&gt;I believe this is related around&amp;nbsp;&lt;SPAN&gt;"Route all traffic"/"Split tunneling"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I found this article but as we are R80.30 I am not sure it applies:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31873" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31873&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does anyone know how I fix this issue?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2019 10:45:30 GMT</pubDate>
    <dc:creator>NeilDavey</dc:creator>
    <dc:date>2019-10-30T10:45:30Z</dc:date>
    <item>
      <title>MAB - Route Traffic via Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66218#M11821</link>
      <description>&lt;P&gt;We use the Mobile Access Blade for connecting into our systems and we also use a PACFILE for internet access.&lt;/P&gt;&lt;P&gt;Once a user has connected onto the MAB, if they untick the PACFILE on IE, then they can get to websites that would be blocked.&lt;/P&gt;&lt;P&gt;Ie - PACFILE would stop access to File Sharing sites, but a user can uncheck the PACFILE and then access File Sharing sites whilst still connected to the MAB.&lt;/P&gt;&lt;P&gt;I believe this is related around&amp;nbsp;&lt;SPAN&gt;"Route all traffic"/"Split tunneling"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I found this article but as we are R80.30 I am not sure it applies:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31873" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31873&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Does anyone know how I fix this issue?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 10:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66218#M11821</guid>
      <dc:creator>NeilDavey</dc:creator>
      <dc:date>2019-10-30T10:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: MAB - Route Traffic via Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66219#M11822</link>
      <description>&lt;P&gt;You mean that you do use a proxy for internet access ? &amp;nbsp;Then why can the clients disable the proxy at all ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 10:49:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66219#M11822</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-30T10:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: MAB - Route Traffic via Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66220#M11823</link>
      <description>Yes that's correct. There is no prevention to stop the users from enabling/disabling this feature.&lt;BR /&gt;&lt;BR /&gt;On occasion, its also useful to be able to perform this for testing.&lt;BR /&gt;&lt;BR /&gt;If a user on the LAN (with a PC) unticks this, then the Firewall blocks the traffic which is normal.&lt;BR /&gt;&lt;BR /&gt;Its only MAB users which have this issue which is why I think its a "Route all traffic"/"Split tunneling" issue.</description>
      <pubDate>Wed, 30 Oct 2019 10:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66220#M11823</guid>
      <dc:creator>NeilDavey</dc:creator>
      <dc:date>2019-10-30T10:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: MAB - Route Traffic via Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66227#M11824</link>
      <description>&lt;P&gt;Says R77 and above&lt;/P&gt;&lt;P&gt;Versions listed mention R80.x but not R80.30 which I suspect is as it hasn't been updated since&amp;nbsp;&lt;SPAN&gt;23-Oct-2018 ie before R80.30 released.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That would then force all traffic up the VPN to the Check Point Gateway as opposed to relying on the fact that the Proxy is seen as reachable via the Gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;That way if disable the PAC when connected to the VPN would still force the traffic over the SNX tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66227#M11824</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-30T11:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: MAB - Route Traffic via Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66230#M11825</link>
      <description>&lt;P&gt;Did you try&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101239&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk101239: &lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;all&lt;/STRONG&gt; &lt;STRONG&gt;traffic&lt;/STRONG&gt; from Remote Access clients, including internet &lt;STRONG&gt;traffic&lt;/STRONG&gt;, through Security Gateway&lt;/A&gt;&amp;nbsp;yet ? You may also need&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122854&amp;amp;partition=Advanced&amp;amp;product=SSL" target="_blank"&gt;sk122854: "You are disconnected, please login again" pop-up appears in SNX window&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 11:56:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MAB-Route-Traffic-via-Gateway/m-p/66230#M11825</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-10-30T11:56:41Z</dc:date>
    </item>
  </channel>
</rss>

