<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New R80.10 ClusterXL gateway cluster VPN NAT issues in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/New-R80-10-ClusterXL-gateway-cluster-VPN-NAT-issues/m-p/15220#M12847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might be worth checking this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31832" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31832"&gt;How to prevent ClusterXL / VRRP / IPSO IP Clustering from hiding its own traffic behind Virtual IP address&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously this is the opposite of what you want, but my thought process is maybe this got configured somehow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Dec 2018 05:06:07 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-15T05:06:07Z</dc:date>
    <item>
      <title>New R80.10 ClusterXL gateway cluster VPN NAT issues</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/New-R80-10-ClusterXL-gateway-cluster-VPN-NAT-issues/m-p/15219#M12846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I built out a new R80.10 ClusterXL gateway (using previous cluster's policy).&amp;nbsp; When I attempt to connect to the remote access VPN using the Virtual IP of the cluster, return traffic is sent back via the physical IP address of the gateway, not the virtual IP.&amp;nbsp; I feel like I just missed a checkbox somewhere, but am not sure where to look.&amp;nbsp; IPSEC gateway to gateway tunnels work fine.&amp;nbsp; I have verified that RADIUS authentication is working and properly authenticating.&amp;nbsp; SSL VPN hangs when authentication is successful (I believe it is because the site is no longer listening on the virtual IP).&amp;nbsp; If anyone has any suggestions, I would really appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2018 17:31:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/New-R80-10-ClusterXL-gateway-cluster-VPN-NAT-issues/m-p/15219#M12846</guid>
      <dc:creator>Steven_Boone</dc:creator>
      <dc:date>2018-12-12T17:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: New R80.10 ClusterXL gateway cluster VPN NAT issues</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/New-R80-10-ClusterXL-gateway-cluster-VPN-NAT-issues/m-p/15220#M12847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might be worth checking this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31832" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31832"&gt;How to prevent ClusterXL / VRRP / IPSO IP Clustering from hiding its own traffic behind Virtual IP address&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously this is the opposite of what you want, but my thought process is maybe this got configured somehow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Dec 2018 05:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/New-R80-10-ClusterXL-gateway-cluster-VPN-NAT-issues/m-p/15220#M12847</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-15T05:06:07Z</dc:date>
    </item>
  </channel>
</rss>

