<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Routing: Route all except for Internet traffic? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/64479#M12754</link>
    <description>Using option 2 you should see traffic for the 3rd party routed through the VPN.</description>
    <pubDate>Mon, 07 Oct 2019 14:51:53 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-10-07T14:51:53Z</dc:date>
    <item>
      <title>VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22913#M12730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we currently have a local Cluster of R77.30 Gateways with many VPN tunnels. We now want to install a bunch of centrally managed 1430 appliances in remote offices.&lt;/P&gt;&lt;P&gt;We normally use VPN Routing "To center, or through the center to other satellites, to internet &lt;STRONG&gt;and other VPN targets&lt;/STRONG&gt;". The problem is that we want a local internet breakout on each remote office but need the "other VPN targets" from our local Cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a possibility to achieve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your help&lt;/P&gt;&lt;P&gt;Marcel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2019 13:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22913#M12730</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-09T13:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22914#M12731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;--sk86582--&lt;/P&gt;&lt;P&gt;$FWDIR/lib/crypt.def&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 10:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22914#M12731</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-10T10:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22915#M12732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know about the crypt.def but I don't understand how I could solve my problem with it. Can I negate the destination IP so that only private IPs are sent through the tunnel? Would something like this work?: &lt;/P&gt;&lt;PRE&gt;vpn_exclude_dst&lt;STRONG&gt;!=&lt;/STRONG&gt;{&amp;lt;10.0.0.0,10.255.255.255&amp;gt;}&lt;/PRE&gt;&lt;P&gt;Maybe you can help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22915#M12732</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-10T12:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22916#M12733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:34:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22916#M12733</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-10T12:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22917#M12734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know how to get this working instead? I can't imagine that this is not possible.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22917#M12734</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-10T12:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22918#M12735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It depends on a use case. The easiest way to set up VPN is to use simplified domain based option. I can only guess why you have decided to go for VPN routing instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 12:58:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22918#M12735</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-10T12:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22919#M12736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To make things clear I made a quick picture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76944_VPN.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Short:&lt;/P&gt;&lt;P&gt;- Our main firewall has many VPN tunnels with other companys etc.&lt;/P&gt;&lt;P&gt;- Our remote offices have one VPN tunnel with our main firewall&lt;/P&gt;&lt;P&gt;- The remote offices have to access the other VPN tunnels through the main firewall&lt;/P&gt;&lt;P&gt;- The remote offices should use the local internet connections&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22919#M12736</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-10T13:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22920#M12737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- The remote offices should use the local internet connections&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a standard S2S VPN setup. Use domain based VPN, it will work out of the box. If you need to route Site 1 to Site 2 through the main FW, there is an option under VPN Community&amp;nbsp;/ VPN Routing to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76945_pastedImage_1.png" /&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This is also written in the documentation, look into the admin guides&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 13:38:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22920#M12737</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-10T13:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22921#M12738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Valeri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does you proposal also cover this requirement ?&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- The remote offices have to access the other VPN tunnels through the main firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;If this explanation is correct&amp;nbsp;&lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/9519-confused-about-vpn-routing-options"&gt;confused-about-vpn-routing-options&lt;/A&gt;&amp;nbsp;(which I believe), then your proposal will only work, if all satellites are in the same VPN community, which is not the case in Macrels setup. Or am I wrong ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Matthias&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 06:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22921#M12738</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2019-01-11T06:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22922#M12739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's exactly my questions here. We normally have one community for a company - thats over 20 in total now. I tested again but it's not working. And I can't just put the remote office in the other community.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 06:13:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22922#M12739</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-11T06:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22923#M12740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcel,&lt;/P&gt;&lt;P&gt;I believe&amp;nbsp; it will work only with a combination of Route Based VPN (for your&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;1430 appliances) and the Domain Based VPNs which I guess you have for your already established VPN Communites.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;A mix of both modes on a gateway is possible as per&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;sk109340&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;But: on a R77.30 Gateway, a Route based VPN would disable CoreXL:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61701&amp;amp;partition=General&amp;amp;product=CoreXL%22"&gt;CoreXL Known Limitations&lt;/A&gt;, an update to R80.x might be an option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Routed based VPN is supported on a 1430 appliance:&amp;nbsp;&lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/Enabling Route Based VPN disables CoreXL functionality on R77.20.xx Gaia Embedded appliances"&gt;Route Based VPN on R77.20.xx Gaia Embedded appliances&lt;/A&gt;&amp;nbsp;but it will also disable Core XL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;You would have to test it carefully of course.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Matthias&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 08:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22923#M12740</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2019-01-11T08:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22924#M12741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Matthias,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help. That sounds like an option but a pretty complex one...if there is no easy way to achieve this we will route all traffic through our main firewall. It works even if it's not the ideal solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jan 2019 10:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22924#M12741</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-11T10:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22925#M12742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You over-complicate the issue. What you need is a single Star VPN community with your main cluster as center and remote offices are satellites.&amp;nbsp; The second option, "to center and other satellites through enter" gives you what you need.&lt;BR /&gt;&lt;BR /&gt;There is one caveat, not related to VPN. Make sure each of satellites has a different internal network IP range OR does unique NAT for internal addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Jan 2019 10:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22925#M12742</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-13T10:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22926#M12743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you want to route traffic between remote sites through the center? Why don't you just use a simple Mesh community and allow the sites to talk to each other directly?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 06:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22926#M12743</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-01-16T06:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22927#M12744</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't want to connect the remote offices but everyone has to access other VPN connections that we don't manage. It's not possible to change the whole VPN contruct here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 06:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22927#M12744</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-16T06:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22928#M12745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It would be nice if I over-complicate the issue but I don't think so. The main point is:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- The remote offices have to access the other VPN tunnels through the main firewall&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Every remote office has to access e.g. the Google Cloud via VPN but the connection has to go through the main firewall. And I cannot build a complete new setup where I only have one community for all VPNs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Your solution doesn't work because the remote offices wouldn't route traffic for the Google Cloud to the main firewall. I double tested this scenario.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 06:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22928#M12745</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-16T06:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22929#M12746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is Google Cloud VPN configured on your main GW? If it is a community, you could enable directional VPN rules in your policy and do something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/77031_pastedImage_1.png" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;You need to configure routing on the main GW that would make sure one tunnel cleart ext would go to another.&lt;BR /&gt;&lt;BR /&gt;Did you consider such setup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 08:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22929#M12746</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-16T08:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22930#M12747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Valeri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for this option I never looked at. It quite nice in some other rules &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;But the problem still exists on the given setup. The problem is that the remote offices try to send traffic to e.g. the Google Cloud through the internet when the VPN routing isn't set to the third option. And if I do that everything is send through the tunnel.&lt;/P&gt;&lt;P&gt;Maybe I misunderstood you but the problem is still the same. And route based VPN is no option because of CoreXL etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any idea left? Maybe it's something that isn't possible no matter how long we think about it...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 12:35:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22930#M12747</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-16T12:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22931#M12748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, how is Google Cloud VPN configured on your main cluster? Is it a community?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 14:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22931#M12748</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-16T14:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Routing: Route all except for Internet traffic?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22932#M12749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, it's configured as a star community with our main cluster as center. VPN routing is set to the second option.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Jan 2019 15:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Routing-Route-all-except-for-Internet-traffic/m-p/22932#M12749</guid>
      <dc:creator>Marcel_Gramalla</dc:creator>
      <dc:date>2019-01-16T15:21:25Z</dc:date>
    </item>
  </channel>
</rss>

