<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access Communities in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/55070#M12821</link>
    <description>&lt;P&gt;HI Nickel.&lt;/P&gt;&lt;P&gt;i'm using an R80.10 vsx GW, and an external MGMT, I try so create a new vpn RemoteAccess community, by clicking on the defoult RemoteAccess and then chosing "new".&lt;/P&gt;&lt;P&gt;So I create a new RemoteAccess.. but it don't works....&lt;/P&gt;&lt;P&gt;i can connect to my second vpn gw installed on a second phisical geographic site, only if I add my second vpn gw on the default RemoteAccess community, otherwise i cannot connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2019 09:20:38 GMT</pubDate>
    <dc:creator>Gabriele_Di_Gia</dc:creator>
    <dc:date>2019-06-05T09:20:38Z</dc:date>
    <item>
      <title>Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17624#M12817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure a more complicated VPN setup for Remote Access but it doesn't look like it works the way i was expecting. There is only one Remote Access Community. In the manual we have the line:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="color: #333333;"&gt;"You can also create a new &lt;STRONG&gt;Remote Access VPN Community&lt;/STRONG&gt; with a different name."&amp;nbsp;&lt;/EM&gt;&lt;SPAN style="color: #333333;"&gt; but there is no instruction on how to do so. If i add new community i have only Star or Mesh options and they look like they are a bit different than the built in Remote Access.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;1. First of all can i have more than one Remote Access Community per Gateway? I can edit VPN Domain per Remote Access but i can't really get how you can create a second Remote Access Community.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333;"&gt;2. I know that there is one Office Mode Pool by default per gateway.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #333333;"&gt;If i need to allocate two different ip subnets to users connecting to the gateway based on Group/Username can i do it in any other way than stated in&amp;nbsp;&lt;SPAN style="font-size: 11.0pt; color: #1f497d;"&gt; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422"&gt;sk33422&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;(Office Mode IP and ipassignment.conf file)&lt;SPAN style="color: #1f497d; font-size: 11.0pt;"&gt;? This one&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. For&amp;nbsp;non-global split-tunnel we have this&lt;SPAN style="color: #1f497d; font-size: 11.0pt;"&gt; &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114882"&gt;sk114882&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;where you can control tunneling mode based on group membership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have a similar setup where let's say?:&lt;/P&gt;&lt;P&gt;Internal VPN Users can access Full-Tunnel and all internal subnets&amp;nbsp;&lt;/P&gt;&lt;P&gt;External VPN Users can access Split-Tunnel and some pre-defined internet destinations with VPN GW NAT&lt;/P&gt;&lt;P&gt;All of this on only one Security Gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Cezar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 10:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17624#M12817</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2018-12-19T10:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17625#M12818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what exactly you're trying to achieve here Cezar? Please explain so we'd have better understanding of your requirements.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 10:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17625#M12818</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2018-12-19T10:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17626#M12819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;I will quote myself:&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Internal VPN Users can access Full-Tunnel and all internal subnets and &lt;SPAN&gt;some pre-defined internet destinations with VPN GW NAT&lt;/SPAN&gt;.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;External VPN Users can access Split-Tunnel and just some pre-defined internet destinations with VPN GW NAT (the specific locations do source filtering and only allow the Customer Companies Subnet to access hence GW has to NAT)&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;All of this on only one Security Gateway&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Internal VPN are employees, External VPN are contractors but everyone will obviously be accessing from the internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2018 10:56:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17626#M12819</guid>
      <dc:creator>cezar_varlan1</dc:creator>
      <dc:date>2018-12-19T10:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17627#M12820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure you need multiple remote access communities if you set the policy up correctly.&lt;/P&gt;&lt;P&gt;That said, I seem to recall someone actually managed to create a second Remote Access community (though I'm not sure how):&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/10089-multiple-remote-access-communities-gw-version" target="_blank"&gt;https://community.checkpoint.com/thread/10089-multiple-remote-access-communities-gw-version&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I know, if you need different pools for different users, you need to edit ipassignment.conf.&lt;/P&gt;&lt;P&gt;Likewise, the other change you mentioned if you want different "split tunnel" settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:07:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/17627#M12820</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/55070#M12821</link>
      <description>&lt;P&gt;HI Nickel.&lt;/P&gt;&lt;P&gt;i'm using an R80.10 vsx GW, and an external MGMT, I try so create a new vpn RemoteAccess community, by clicking on the defoult RemoteAccess and then chosing "new".&lt;/P&gt;&lt;P&gt;So I create a new RemoteAccess.. but it don't works....&lt;/P&gt;&lt;P&gt;i can connect to my second vpn gw installed on a second phisical geographic site, only if I add my second vpn gw on the default RemoteAccess community, otherwise i cannot connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 09:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/55070#M12821</guid>
      <dc:creator>Gabriele_Di_Gia</dc:creator>
      <dc:date>2019-06-05T09:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/55073#M12822</link>
      <description>&lt;P&gt;What about using&amp;nbsp;Remote Access Roles&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;in your&amp;nbsp;&lt;/SPAN&gt;Remote Access Control Policy&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;? You can use different rules to control&amp;nbsp;&lt;/SPAN&gt;access of User Groups, see&amp;nbsp;Remote Access VPN Administration Guide R80.20 p. 28f for details !&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 10:06:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/55073#M12822</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-06-05T10:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/178601#M12823</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"i can connect to my second vpn gw installed on a second phisical geographic site, only if I add my second vpn gw on the default RemoteAccess community, otherwise i cannot connect."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi, I know this was a while ago, but if I add the 2nd gateway to the default RemoteAccess community, then the users can connect, but cannot access any network facilities.&amp;nbsp; How did you get around this issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 09:42:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/178601#M12823</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-20T09:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/178622#M12824</link>
      <description>&lt;P&gt;I'd like to see your trac.log - It might be that you have overlapping encryption domains between the two gateways.&amp;nbsp; Have a look at&amp;nbsp;&lt;SPAN&gt;sk78180.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 13:40:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/178622#M12824</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-04-20T13:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Communities</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/179033#M12825</link>
      <description>&lt;P&gt;Where can I find the trac.log? &lt;STRONG&gt;&lt;EM&gt;find / -name trac.log&lt;/EM&gt;&lt;/STRONG&gt; returns nothing.&lt;/P&gt;&lt;P&gt;SK78180 directs me to disable MEP.&amp;nbsp; Is that correct?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Communities/m-p/179033#M12825</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-25T08:12:41Z</dc:date>
    </item>
  </channel>
</rss>

