<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Mobile VPN issue in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36782#M13112</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Please verify that the server&amp;nbsp;10.8.251.187 has a return route to the IP Pool on Syd Firewall. Run traceroute on it to see where it goes.&lt;/P&gt;&lt;P&gt;2. Please verify that the Mel VPN is NOT active on the remote user's laptop at the time of the test and that there are no residual or static routes present on it that may skew the test.&lt;/P&gt;&lt;P&gt;3. You have common VPN community servicing both gateways for the same destination. Is that community configured as MEP (Multiple Entry Points)?&lt;/P&gt;&lt;P&gt;4. The logs you are looking at may be filtered, please remove filters if any present.&lt;/P&gt;&lt;P&gt;5. If the community is not a MEP, consider creating a separate community by cloning "Remote Access" and creating two sets of rules for VPN with target gateways defined in each rule.&lt;/P&gt;&lt;P&gt;6. Your 10.0.0.0/8 route is too broad and includes your IP Pools. It'd be cleaner to have a different range for Remote Clients, such as 172.16... or 192.168.255... (just NOT 192.168.0.0 or 192.168.1.0).&lt;/P&gt;&lt;P&gt;7. Check if your Syd "CP_default_Office_Mode_addresses_pool" or whatever network you have defined for it is NATed to hide behind gateway. Compare to Mel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Oct 2018 12:37:42 GMT</pubDate>
    <dc:creator>Vladimir</dc:creator>
    <dc:date>2018-10-22T12:37:42Z</dc:date>
    <item>
      <title>Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36774#M13104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I've set up our Sydney 12200 Check Point FW as a VPN GW for remote users.&lt;/P&gt;&lt;P&gt;The FW communicates with our RSA ACE and this is working well&lt;/P&gt;&lt;P&gt;Test users can authenticate and obtain the VPN IP address, also performing a"route print" the laptops have learnt all the internal routes.&lt;/P&gt;&lt;P&gt;The issue is the laptops cannot access the internal network and the FW logs do not show any traffic from the laptops to the destination. Performing a tracert to an internal destination fails at first hop.&lt;/P&gt;&lt;P&gt;The Sydney FW has the correct static routes configured and itself can access internal networks.&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 03:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36774#M13104</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-19T03:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36775#M13105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Surely when the VPN clients connect and authenticate, there are logs, correct?&lt;/P&gt;&lt;P&gt;Also, have you done a tcpdump when a VPN client tries to communicate to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;See if the packets actually leave the Security Gateway&lt;/LI&gt;&lt;LI&gt;See if there are any responses received to said packets (e.g. ping)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect the issue is the rest of your network doesn't know where to direct the reply packets for your VPN clients.&lt;/P&gt;&lt;P&gt;Depending on your exact topology and the Office Mode IPs, we can provide a bit more specific advice.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 16:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36775#M13105</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-19T16:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36776#M13106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The obvious question: do you have access rules permitting your remote clients communication with internal networks?&lt;/P&gt;&lt;P&gt;If you are not seeing the attempts in the logs, you likely have a cleanup rule with "drop" and "do not log" in your policy that behaves as it should. Enable logging on it for troubleshooting to see the drops.&lt;/P&gt;&lt;P&gt;There are also Implied rules that are not logged that you can enable logging in the "Global" properties for troubleshooting.&lt;/P&gt;&lt;P&gt;Do remember to change those back to "do not log" to avoid flooding your log server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Oct 2018 00:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36776#M13106</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-20T00:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36777#M13107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon and Vladimir&lt;/P&gt;&lt;P&gt;Thanks for getting back to me.&lt;/P&gt;&lt;P&gt;Using FW monitor and tcp dump there are no packets when generating traffic. There are packets where the VPN client is communicating to the FW on rule 0 but these packets are generated whether or not the client is trying to communicate inside.&lt;/P&gt;&lt;P&gt;The FW's have the correct routes to the inside network and the policy permits the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Oct 2018 22:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36777#M13107</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-21T22:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36778#M13108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kindly paste the subset of the rulebase you have defined for VPN in this thread.&lt;/P&gt;&lt;P&gt;It would also help to see the diagram of the network you are working with as well as a printout of active routes.&lt;/P&gt;&lt;P&gt;As to a traceroute, enable "Accept ICMP" in the global properties to see the traversal of the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 00:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36778#M13108</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-22T00:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36779#M13109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The basic diagram attached&lt;/P&gt;&lt;P&gt;The policy for our Mel and Syd are shared by the FW’s thus there is only one policy for both.&lt;/P&gt;&lt;P&gt;Mel VPN uses the rules below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’ve enabled #Accept ICMP” in the global properties now and installed the policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 01:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36779#M13109</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-22T01:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36780#M13110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the only traffic logs generated – tunnel tests. 10.128.99.21 is the Mgmt interface and not the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 01:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36780#M13110</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-22T01:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36781#M13111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A version of the diagram as a PDF or JPG would be preferable.&lt;/P&gt;&lt;P&gt;Also keep in mind this is a public forum and you may wish to mask sensitive data.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 04:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36781#M13111</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-22T04:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36782#M13112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. Please verify that the server&amp;nbsp;10.8.251.187 has a return route to the IP Pool on Syd Firewall. Run traceroute on it to see where it goes.&lt;/P&gt;&lt;P&gt;2. Please verify that the Mel VPN is NOT active on the remote user's laptop at the time of the test and that there are no residual or static routes present on it that may skew the test.&lt;/P&gt;&lt;P&gt;3. You have common VPN community servicing both gateways for the same destination. Is that community configured as MEP (Multiple Entry Points)?&lt;/P&gt;&lt;P&gt;4. The logs you are looking at may be filtered, please remove filters if any present.&lt;/P&gt;&lt;P&gt;5. If the community is not a MEP, consider creating a separate community by cloning "Remote Access" and creating two sets of rules for VPN with target gateways defined in each rule.&lt;/P&gt;&lt;P&gt;6. Your 10.0.0.0/8 route is too broad and includes your IP Pools. It'd be cleaner to have a different range for Remote Clients, such as 172.16... or 192.168.255... (just NOT 192.168.0.0 or 192.168.1.0).&lt;/P&gt;&lt;P&gt;7. Check if your Syd "CP_default_Office_Mode_addresses_pool" or whatever network you have defined for it is NATed to hide behind gateway. Compare to Mel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 12:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36782#M13112</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-10-22T12:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36783#M13113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Vladimir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some excellent points to investigate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  1.  10.8.251.187 routes correctly via Syd FW for 10.15.16.x&lt;/P&gt;&lt;P&gt;  2.  Mel VPN is removed from the client VPN so is not active at the time of the tests.&lt;/P&gt;&lt;P&gt;  3.  Good point, I will investigate this.&lt;/P&gt;&lt;P&gt;  4.  Good point, I will investigate this&lt;/P&gt;&lt;P&gt;  5.  Good point, I will investigate this&lt;/P&gt;&lt;P&gt;  6.  Agree.&lt;/P&gt;&lt;P&gt;  7.  Good point, I will investigate this&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 21:21:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36783#M13113</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-22T21:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Mobile VPN issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36784#M13114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RemoteAccess community is a star topology with no way to prevision MEP, see below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot clone this community, copy is available though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another colleague stated they could access the network from their home computer with the VPN client installed.&lt;/P&gt;&lt;P&gt;I am going to try the same when I get home tonight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2018 04:28:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Mobile-VPN-issue/m-p/36784#M13114</guid>
      <dc:creator>alan_garnham</dc:creator>
      <dc:date>2018-10-23T04:28:27Z</dc:date>
    </item>
  </channel>
</rss>

