<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Guest network and mobile access on same public IP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13826#M12985</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration is set on R80.10 version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a guest access with NAT IP public, this access is for web access with some limitations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But somes times, internal users as don't have access to internal network , use this guest access to connect to VPN ( this VPN is a mobile access and configured with the same public IP of guest access ), but not works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checking logs I see&amp;nbsp;that all traffiic is drop&amp;nbsp;because anti-spoofing protection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know it's possible to make this configuration without disable&amp;nbsp;&lt;SPAN&gt;anti-spoofing protection&amp;nbsp; ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Marco&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Nov 2018 17:45:56 GMT</pubDate>
    <dc:creator>sys_Admin1</dc:creator>
    <dc:date>2018-11-06T17:45:56Z</dc:date>
    <item>
      <title>Guest network and mobile access on same public IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13826#M12985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration is set on R80.10 version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a guest access with NAT IP public, this access is for web access with some limitations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But somes times, internal users as don't have access to internal network , use this guest access to connect to VPN ( this VPN is a mobile access and configured with the same public IP of guest access ), but not works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checking logs I see&amp;nbsp;that all traffiic is drop&amp;nbsp;because anti-spoofing protection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know it's possible to make this configuration without disable&amp;nbsp;&lt;SPAN&gt;anti-spoofing protection&amp;nbsp; ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Marco&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 17:45:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13826#M12985</guid>
      <dc:creator>sys_Admin1</dc:creator>
      <dc:date>2018-11-06T17:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Guest network and mobile access on same public IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13827#M12986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A few more details are needed here.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is your guest network included as part of the Encryption Domain (Gateway object &amp;gt; Network Management &amp;gt; VPN Domain)&lt;UL&gt;&lt;LI&gt;If you're using All IPs Behind Gateway, then it is and you should use an explicit domain definite that excludes this network.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;A screenshot of the anti-spoofing message would be exceptionally helpful along with related topology information&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 21:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13827#M12986</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-06T21:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Guest network and mobile access on same public IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13828#M12987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network guest is not part of&amp;nbsp;e&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;ncryption&lt;SPAN&gt;&amp;nbsp;domain and f&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.5pt; color: #3d3d3d; background: white;"&gt;or mobile access I using a specific domain&amp;nbsp;&lt;/SPAN&gt;and not include the guest network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the message with drop packets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73255_Capture.PNG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Marco&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 10:55:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13828#M12987</guid>
      <dc:creator>sys_Admin1</dc:creator>
      <dc:date>2018-11-07T10:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Guest network and mobile access on same public IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13829#M12988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Need to see the entire log card, not just the message.&lt;/P&gt;&lt;P&gt;Also need to understand the topology.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 15:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13829#M12988</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-07T15:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Guest network and mobile access on same public IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13830#M12989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I solved my issue with&amp;nbsp;sk44075. Apply solution for&amp;nbsp;Cause 2: Office Mode IP Pool is part of the VPN Encryption Domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Marco&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 15:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Guest-network-and-mobile-access-on-same-public-IP/m-p/13830#M12989</guid>
      <dc:creator>sys_Admin1</dc:creator>
      <dc:date>2018-11-07T15:58:17Z</dc:date>
    </item>
  </channel>
</rss>

