<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split Tunnel in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/100565#M13446</link>
    <description>&lt;P&gt;if im using splittunnel setup and i would like to have the same rules, that is: a user should not have access to socialmedia when he is at the office and also when he is using splittunnel vpn. what do you suggest in this case?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 14:58:50 GMT</pubDate>
    <dc:creator>Itops</dc:creator>
    <dc:date>2020-10-29T14:58:50Z</dc:date>
    <item>
      <title>Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34675#M13437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help how to do split tunnel. I want to force the traffic of the VPN user to use their local internet provider when connected to the VPN tunnel so it will not consume the bandwidth of the company.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 04:09:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34675#M13437</guid>
      <dc:creator>Juan_Karlo_Cris</dc:creator>
      <dc:date>2018-06-28T04:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34676#M13438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Split tunneling is enabled by default. you don't have to do anything.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 14:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34676#M13438</guid>
      <dc:creator>Houssameddine_1</dc:creator>
      <dc:date>2018-06-28T14:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34677#M13439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah Correct. Split tunneling is enabled by default for remote VPN users. You need to enable setting if you don't want split tunneling but by default it is enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 12:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34677#M13439</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-06-29T12:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34678#M13440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Juan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration is done in&amp;nbsp;Global Properties. It&amp;nbsp;is&amp;nbsp;enabled by default. Configure the option "Route all traffic to gateway" to "No".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also set it to "Configured on endpoint client", so the user can route everything through gateway to be&amp;nbsp;safer when needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Configure split tunnel" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66859_SplitTunnel.PNG" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 15:05:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/34678#M13440</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-06-29T15:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87038#M13441</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;How to add a route in the routing table of the Remote Access VPN user?</description>
      <pubDate>Tue, 02 Jun 2020 09:08:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87038#M13441</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-02T09:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87108#M13442</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Sanjay_S,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What's your final goal: to forward traffic to encryption domain or to exclude some traffic from encryption domain?&lt;/P&gt;
&lt;P&gt;Are you working in hub mode when all traffic is routed to gateway or in regular mode (split tunnel) when non-encryption domain traffic is not routed to gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 20:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87108#M13442</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2020-06-02T20:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87140#M13443</link>
      <description>Hi AndreiR,&lt;BR /&gt;We are using Split tunnel mode. My goal is to add an additional subnet in the route table of the user machine when connected to Checkpoint endpoint security for a subnet and that should be routed towards Gateway.</description>
      <pubDate>Wed, 03 Jun 2020 07:51:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87140#M13443</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-06-03T07:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87450#M13444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18584"&gt;@Sanjay_S&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You may manually define VPN domain. Open Smart Console, open properties for specific gateway, go to Network Management –&amp;gt; VPN Domain. There you can select "Manual defined" and specify VPN domain using predefined network objects.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 17:56:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/87450#M13444</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2020-06-05T17:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/100565#M13446</link>
      <description>&lt;P&gt;if im using splittunnel setup and i would like to have the same rules, that is: a user should not have access to socialmedia when he is at the office and also when he is using splittunnel vpn. what do you suggest in this case?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 14:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/100565#M13446</guid>
      <dc:creator>Itops</dc:creator>
      <dc:date>2020-10-29T14:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116091#M13447</link>
      <description>&lt;P&gt;I also want to do this.&amp;nbsp; I do not want to enable hub mode, but want to add additional subnet range of a 3rd party website.&lt;/P&gt;&lt;P&gt;I added the external range to my VPN Domain, but still no luck.&lt;/P&gt;&lt;P&gt;I don't even see any blocked packets in the Logs (either before or after the change).&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 09:50:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116091#M13447</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2021-04-15T09:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116121#M13448</link>
      <description>&lt;P&gt;Hi AndreiR,&lt;/P&gt;&lt;P&gt;You just need to add the new subnet in the VPN Domain.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 13:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116121#M13448</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-04-15T13:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116123#M13449</link>
      <description>&lt;P&gt;Thanks! That's worked!!&amp;nbsp; I changed the wrong object at first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 13:39:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/116123#M13449</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2021-04-15T13:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157677#M13450</link>
      <description>&lt;P&gt;So at the moment I am routing all traffic to the gateway for my vpn set up. I want to only allow office 365 to break out locally on the endpoint. Do I have to turn off hub mode and select "No" to route all traffic to the gateway and just rely on the vpn domain to route traffic into my gateway. hope that makes sense....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 21:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157677#M13450</guid>
      <dc:creator>alancw</dc:creator>
      <dc:date>2022-09-20T21:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157678#M13451</link>
      <description>&lt;P&gt;Have you reviewed&amp;nbsp;&lt;SPAN&gt;sk167000 for your use case?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2022 23:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157678#M13451</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-20T23:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157720#M13452</link>
      <description>&lt;P&gt;Nice one thanks very much for that Chris.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 12:12:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157720#M13452</guid>
      <dc:creator>alancw</dc:creator>
      <dc:date>2022-09-21T12:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157761#M13453</link>
      <description>&lt;P&gt;Hi Chris, I used this SK tonight on our environment but it totally broke traffic going over the remote access vpn for some reason.&lt;/P&gt;&lt;P&gt;The IP Addresses for office 365 did route out the broadband which was all good. But all traffic back to the firewalls did not work.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 21:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157761#M13453</guid>
      <dc:creator>alancw</dc:creator>
      <dc:date>2022-09-21T21:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157764#M13454</link>
      <description>&lt;P&gt;Do you try using ANY and or ALL INTERNET when configuring your group with exclusions?&lt;/P&gt;
&lt;P&gt;Other than trying these alternatives I would suggest diagnosing further with the TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 23:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/157764#M13454</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-09-21T23:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/158672#M13455</link>
      <description>&lt;P&gt;Yeah I tried to use "ANY" and I created a "ALL INTERNET" 0.0.0.0/0 to test but i only got some internal subnets working which is really weird. Do you know of any file on the manager that sends out the encryption domain to the client? that contains the subnets to encrypt?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 10:35:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/158672#M13455</guid>
      <dc:creator>alancw</dc:creator>
      <dc:date>2022-10-03T10:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/158673#M13456</link>
      <description>&lt;P&gt;What Endpoint client version is used here?&lt;/P&gt;
&lt;P&gt;To further expedite this I would recommend contacting TAC as above.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 10:45:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/158673#M13456</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-03T10:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/172257#M13457</link>
      <description>&lt;P&gt;Onto TAC now for the last 3 months, with no sign of fixing the issue that I have. has anyone else had this sort of issue before? Was there any way around this?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 22:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel/m-p/172257#M13457</guid>
      <dc:creator>alancw</dc:creator>
      <dc:date>2023-02-21T22:56:40Z</dc:date>
    </item>
  </channel>
</rss>

