<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cluster as a vpn server and proxy server in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9515#M13360</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are some things to check:&lt;/P&gt;&lt;P&gt;Make sure to add the internal Proxy IP to the remote access VPN topology.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the rule allowing access to the proxy contain the Officemode IP range as source?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you want them to use explicit Proxy?&amp;nbsp; Is it due to the fact it is already set for the corporate network?&lt;/P&gt;&lt;P&gt;When you use a PAC or WPAD.dat file you could exclude the Officemode network from the proxy and when set to hubmode, you can still force all traffic through the FW and apply a "at home" policy to that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The gateway can be used as transparant and explicit proxy at the same time. Doing the same on a 15600 with about 600Mbps fully filtered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jul 2018 22:00:06 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2018-07-17T22:00:06Z</dc:date>
    <item>
      <title>cluster as a vpn server and proxy server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9514#M13359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;now i use my Checkpoint cluster as a corporate non&amp;nbsp; transparent proxy server. Additionally to that i use it as a vpn server for my remote access users. Now my current task is configure so my remote access users can use my proxy server to reach internet resouces according to the Access Policy on my cluster. in case If i define internal interfaces ip address of cluster as a proxy (on my vpn users browser settings) - web pages cannot be displayed. in case if i define&amp;nbsp;external&amp;nbsp;&lt;SPAN&gt;interfaces ip address of cluster as a proxy (on my vpn users browser settings)&amp;nbsp; - users can open web pages, but they have unlimited access to internet (access not restricted according to Access Policy on my cluster).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;how to solve this&amp;nbsp;task?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67069_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2018 11:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9514#M13359</guid>
      <dc:creator>Dilmurat_Zakiro</dc:creator>
      <dc:date>2018-07-17T11:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: cluster as a vpn server and proxy server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9515#M13360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are some things to check:&lt;/P&gt;&lt;P&gt;Make sure to add the internal Proxy IP to the remote access VPN topology.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the rule allowing access to the proxy contain the Officemode IP range as source?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why do you want them to use explicit Proxy?&amp;nbsp; Is it due to the fact it is already set for the corporate network?&lt;/P&gt;&lt;P&gt;When you use a PAC or WPAD.dat file you could exclude the Officemode network from the proxy and when set to hubmode, you can still force all traffic through the FW and apply a "at home" policy to that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The gateway can be used as transparant and explicit proxy at the same time. Doing the same on a 15600 with about 600Mbps fully filtered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2018 22:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9515#M13360</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-17T22:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: cluster as a vpn server and proxy server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9516#M13361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Q:Does the rule allowing access to the proxy contain the Officemode IP range as source?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;A:yes, clients can reach proxy by its tcp port 8080. connection established, logs confirm that fact&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Q:&lt;SPAN&gt;Why do you want them to use explicit Proxy?&amp;nbsp; Is it due to the fact it is already set for the corporate network?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;A:the main task is configure access for remote access users in order to they have the same Access policy both when they are&amp;nbsp; in corporate network and when connected via vpn client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Q:&lt;SPAN&gt;When you use a PAC or WPAD.dat file you could exclude the Officemode network from the proxy and when set to hubmode, you can still force all traffic through the FW and apply a "at home" policy to that traffic.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;A: Can you explain how i can implement it(is there any useful/helpful link? i never did anything like that)? does it mean that i can configure the same policy as on my security gateway for my remote access clients?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 10:15:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9516#M13361</guid>
      <dc:creator>Dilmurat_Zakiro</dc:creator>
      <dc:date>2018-07-18T10:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: cluster as a vpn server and proxy server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9517#M13362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Q1: Do you also see a request from the gateway to the requested site? Or does the FW (Security Gateway) give the user a blockpage (which might not be shown)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2: So you can achieve that by just making sure that all traffic is routed through the FW when connected. Go into the Global Properties and select Remote Access -&amp;gt; Endpoint Securrity VPN, now under Security Settings the first item is Route all traffic to gateway, there select Yes. Now open the&amp;nbsp;FW Object&amp;nbsp;&amp;nbsp;got to VPN Clients -&amp;gt; Remote Access, here you will find the option "Allow VPN Clients to route all traffic through the gateway" under Hub Mode configuration, set it to on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q3: How to set up a Proxy.pac file and how to use it has many results in all search engines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Transparant and proxied is only controlled by policy, if traffic is allowed by a specific rule it will be allowed to go through that part of the policy, so if you have an inline Application policy just make sure to allow the Officemode network to use that rule by adding it to the source. Do not forget to set a NAT rule for outbound traffic from the officemode network and two rules above it that disables NAT for inbound from the clients and vice versa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2018 12:56:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/cluster-as-a-vpn-server-and-proxy-server/m-p/9517#M13362</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-18T12:56:38Z</dc:date>
    </item>
  </channel>
</rss>

