<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN Reply Interface in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28161#M13522</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just want to know if anyone had a problem with outgoing traffic reply for VPN Remote Access, i just found out that when you try to establish the VPN tunnel with Remote Access on checkpoint it tries to reply using the default route of the Gateway, even if you have two external interfaces it does not use the setting on IPSec link selection (Reply from the same interface) and because of this the VPN tunnel cannot be establish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use PBR for this but it also didnt worked, and i tried to found out something related to this on support center but didnt found anything, i think this is by design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have a clue how to solve this? I had changed the default route to the other ISP interface (The one used by VPN Remote) and it worked, but i cant let this configured becase the users use the other link for internet access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Jun 2018 14:53:52 GMT</pubDate>
    <dc:creator>Hugo_Frauches</dc:creator>
    <dc:date>2018-06-04T14:53:52Z</dc:date>
    <item>
      <title>Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28161#M13522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just want to know if anyone had a problem with outgoing traffic reply for VPN Remote Access, i just found out that when you try to establish the VPN tunnel with Remote Access on checkpoint it tries to reply using the default route of the Gateway, even if you have two external interfaces it does not use the setting on IPSec link selection (Reply from the same interface) and because of this the VPN tunnel cannot be establish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use PBR for this but it also didnt worked, and i tried to found out something related to this on support center but didnt found anything, i think this is by design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have a clue how to solve this? I had changed the default route to the other ISP interface (The one used by VPN Remote) and it worked, but i cant let this configured becase the users use the other link for internet access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Jun 2018 14:53:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28161#M13522</guid>
      <dc:creator>Hugo_Frauches</dc:creator>
      <dc:date>2018-06-04T14:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28162#M13523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is by design according to this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk76281" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk76281"&gt;Outgoing VPN Link Selection on a gateway with multiple external interfaces&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you can use VSX to work around this limitation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jun 2018 04:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28162#M13523</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-05T04:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28163#M13524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the reply, unfortunately we do not have an VSX. The way i manage to overcome this by design setting was doing a NAT to the other external interface, now the outgoing traffic works and goes to the same interface!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 13:37:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28163#M13524</guid>
      <dc:creator>Hugo_Frauches</dc:creator>
      <dc:date>2018-06-07T13:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28164#M13525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hugo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please provide to us more details concerning NAT configuration?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;BR,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 10:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28164#M13525</guid>
      <dc:creator>Konstantinos_In</dc:creator>
      <dc:date>2018-07-09T10:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28165#M13526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since this limitation its by design in the Checkpoint Gateway, i had to create an external NAT on my ISP router from the other external interface mapping to the VIP interface on the cluster, doing that i could create the remote access VPN connection, since this time the Inbound/Outbound traffic was using the same external interface.&lt;BR /&gt;&lt;BR /&gt;This its not an workaround on the Checkpoint configuration, its only a workaround on our topology to bypass this limitation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 16:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28165#M13526</guid>
      <dc:creator>Hugo_Frauches</dc:creator>
      <dc:date>2018-07-09T16:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Reply Interface</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28166#M13527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Hugo &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 08:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Reply-Interface/m-p/28166#M13527</guid>
      <dc:creator>Konstantinos_In</dc:creator>
      <dc:date>2018-07-11T08:02:49Z</dc:date>
    </item>
  </channel>
</rss>

