<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude Subnet in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/80347#M13626</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;says, you can use '&lt;SPAN&gt;exclude_local_networks_in_hub_mode' attribute in the&amp;nbsp;trac_client_1.ttm to exclude a user's local network when they're connected to Remote Access VPN and using hub mode...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;You can go for a more manual and&amp;nbsp;&lt;SPAN&gt;customisable&lt;/SPAN&gt; approach where you manually exclude any host/network required, rather than just being limited to the excluding a user's local network.&lt;/P&gt;&lt;P&gt;If you'd like configure the Remote Access routing to essentially route all traffic to the gateway, EXCEPT a certain list of hosts/subnets, then you need to do the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Ensure "Route all traffic to gateway" is set to NO in Global Properties &amp;gt; Remote Access &amp;gt; SecureClient Mobile &amp;amp; Endpoint Connect.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Ensure Hub Mode is set to ALLOW on the gateway object under VPN Clients &amp;gt; Remote Access.&lt;/LI&gt;&lt;LI&gt;Create a new network group named 'All_Internet_Group', and add the default 'All_Internet' object to it.&lt;/LI&gt;&lt;LI&gt;Create a new network group named 'ED-RemoteAccess_Exclusions'. Add all of the hosts/networks you'd like to be excluded from hub mode (I.E, routed locally on the client's end rather than across the VPN to the gateway).&lt;/LI&gt;&lt;LI&gt;Create a new "group with exclusions" called 'ED-RemoteAccess', reference the&amp;nbsp;'All_Internet_Group' we created as the main group and the&amp;nbsp;'ED-RemoteAccess_Exclusions' we created as the exclusion group.&lt;/LI&gt;&lt;LI&gt;Set the&amp;nbsp;'ED-RemoteAccess' group as the Remote Access encryption domain on the gateway topology.&lt;/LI&gt;&lt;LI&gt;Ensure security rules and NAT rules are setup to support this configuration (I.E, security rules allow the OfficeMode subnet access to the Internet, and the OfficeMode subnet is NAT'd behind the gateway).&lt;/LI&gt;&lt;LI&gt;Install policy, then disconnect/reconnect any existing connected clients so that they get the new routing table.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To put this into a scenario, lets say you want all traffic to be routed to the gateway (like it is in hub mode), apart from 167.20.10.0/24 (some random network I thought of, insert yours here) - you want the clients to route this out of their local connection rather than via the security gateway. Following the scenario above and adding the&amp;nbsp;167.20.10.0/24 network to the 'ED-RemoteAccess_Exclusions' group will achieve this.&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;Luke&lt;/P&gt;</description>
    <pubDate>Mon, 06 Apr 2020 20:03:05 GMT</pubDate>
    <dc:creator>LukeOxley</dc:creator>
    <dc:date>2020-04-06T20:03:05Z</dc:date>
    <item>
      <title>Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23602#M13614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;I don't want to configure split tunnel on the security gateway, I was wondering how I can exclude my subnet from full tunnel setup, is there any options?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 14:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23602#M13614</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-11T14:06:24Z</dc:date>
    </item>
    <item>
      <title>Re:  Question- Cant Access Local VMs when on VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23603#M13615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let's put this in the &lt;A href="https://community.checkpoint.com/space/2056"&gt;Remote Access&lt;/A&gt;‌ section where it belongs.&lt;/P&gt;&lt;P&gt;Looks like you can achieve what you're after by following this SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121766" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121766"&gt;Cannot exclude local network when connected to Remote Access VPN via Hub Mode&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 15:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23603#M13615</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-11T15:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23604#M13616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon, I followed your SK but it didnt help.&lt;/P&gt;&lt;P&gt;When ever I try to access a local resource (local VM on my PC), the traffic is still being sent through to SG.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to find a solution where i can have split tunnel enabled for my VPN (exclude local subnet going through SG which is enabled for hub mode)&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 07:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23604#M13616</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-23T07:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23605#M13617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps there is an error in the SK or there is a different issue.&lt;/P&gt;&lt;P&gt;Have you opened a TAC case?&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://www.checkpoint.com/support-services/contact-support/" title="https://www.checkpoint.com/support-services/contact-support/"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23605#M13617</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-23T08:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23606#M13618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not as I dont have support contract with CP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I there any solution where i can have split tunnel enabled for certain users on Checkpoint and other users will have to go through SG which is configured for Hub Mode? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:35:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23606#M13618</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-23T08:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23607#M13619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know this is a global setting.&lt;/P&gt;&lt;P&gt;That means either all users can do it or none can.&lt;/P&gt;&lt;P&gt;Did you modify trac_client_1.ttm as described in the SK?&lt;/P&gt;&lt;P&gt;Your partner (or whoever you have a support contract they) should be able to open a ticket with us as needed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 08:52:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23607#M13619</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-23T08:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23608#M13620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any other option other than sk121766, to exclude local subnet from going through security gateways which is configured for HUB mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I want to have split tunnel enabled for only specific users and other users I they will have to go through SG which is configured for Hub Mode?&lt;/P&gt;&lt;P&gt;Is it possible to configure split tunnel for some and full tunnel for other users ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 09:24:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23608#M13620</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-23T09:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23609#M13621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know the settings apply to all users connecting to a given gateway but will double-check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 14:30:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23609#M13621</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-23T14:30:25Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23610#M13622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2018 20:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23610#M13622</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-23T20:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23611#M13623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you can configure the TTM file per group.&lt;/P&gt;&lt;P&gt;In fact, the exact scenario you want is described in the following SK:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114882" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114882"&gt;Remote Access clients configuration based on group membership&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 15:35:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23611#M13623</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-24T15:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23612#M13624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 20:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23612#M13624</guid>
      <dc:creator>jessica_smith</dc:creator>
      <dc:date>2018-05-24T20:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23613#M13625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jessica,&lt;/P&gt;&lt;P&gt;Did you got the solution&amp;nbsp; for remote access vpn tunnel requirement?.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2018 10:34:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/23613#M13625</guid>
      <dc:creator>rajesh_s</dc:creator>
      <dc:date>2018-10-30T10:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Subnet</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/80347#M13626</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;says, you can use '&lt;SPAN&gt;exclude_local_networks_in_hub_mode' attribute in the&amp;nbsp;trac_client_1.ttm to exclude a user's local network when they're connected to Remote Access VPN and using hub mode...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;You can go for a more manual and&amp;nbsp;&lt;SPAN&gt;customisable&lt;/SPAN&gt; approach where you manually exclude any host/network required, rather than just being limited to the excluding a user's local network.&lt;/P&gt;&lt;P&gt;If you'd like configure the Remote Access routing to essentially route all traffic to the gateway, EXCEPT a certain list of hosts/subnets, then you need to do the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Ensure "Route all traffic to gateway" is set to NO in Global Properties &amp;gt; Remote Access &amp;gt; SecureClient Mobile &amp;amp; Endpoint Connect.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Ensure Hub Mode is set to ALLOW on the gateway object under VPN Clients &amp;gt; Remote Access.&lt;/LI&gt;&lt;LI&gt;Create a new network group named 'All_Internet_Group', and add the default 'All_Internet' object to it.&lt;/LI&gt;&lt;LI&gt;Create a new network group named 'ED-RemoteAccess_Exclusions'. Add all of the hosts/networks you'd like to be excluded from hub mode (I.E, routed locally on the client's end rather than across the VPN to the gateway).&lt;/LI&gt;&lt;LI&gt;Create a new "group with exclusions" called 'ED-RemoteAccess', reference the&amp;nbsp;'All_Internet_Group' we created as the main group and the&amp;nbsp;'ED-RemoteAccess_Exclusions' we created as the exclusion group.&lt;/LI&gt;&lt;LI&gt;Set the&amp;nbsp;'ED-RemoteAccess' group as the Remote Access encryption domain on the gateway topology.&lt;/LI&gt;&lt;LI&gt;Ensure security rules and NAT rules are setup to support this configuration (I.E, security rules allow the OfficeMode subnet access to the Internet, and the OfficeMode subnet is NAT'd behind the gateway).&lt;/LI&gt;&lt;LI&gt;Install policy, then disconnect/reconnect any existing connected clients so that they get the new routing table.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;To put this into a scenario, lets say you want all traffic to be routed to the gateway (like it is in hub mode), apart from 167.20.10.0/24 (some random network I thought of, insert yours here) - you want the clients to route this out of their local connection rather than via the security gateway. Following the scenario above and adding the&amp;nbsp;167.20.10.0/24 network to the 'ED-RemoteAccess_Exclusions' group will achieve this.&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;&lt;P&gt;Luke&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 20:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Exclude-Subnet/m-p/80347#M13626</guid>
      <dc:creator>LukeOxley</dc:creator>
      <dc:date>2020-04-06T20:03:05Z</dc:date>
    </item>
  </channel>
</rss>

