<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable SNX on Cluster in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20513#M13700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chance the border router can perform the public &amp;gt; private NAT?&lt;/P&gt;&lt;P&gt;That seems like it might be the cleanest solution here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 May 2018 19:22:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-05-01T19:22:15Z</dc:date>
    <item>
      <title>Enable SNX on Cluster</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20512#M13699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to enable mobile access on our HA (active/passive) cluster to be able to use SNX.&amp;nbsp; Right now I'm stuck on just getting the web page with the user/pass field.&amp;nbsp;&amp;nbsp;Our topology looks something like this (w/ IPs changed)&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="65217" alt="" class="image-1 jive-image" height="519" src="/legacyfs/online/checkpoint/65217_Screen Shot 2018-05-01 at 12.16.50 PM.png" width="440" /&gt;&lt;/P&gt;&lt;P&gt;Computers on the internal networks can open a webpage to 192.168.0.5 with the expected portal.&amp;nbsp; But I want remote users on the public internet to be able to access the portal page.&amp;nbsp; So I created a DNS entry vpn.ourdomain.com to resolve to a public IP address and during the first time setup wizard I told the portal to use that FQDN.&amp;nbsp; I created access control rules to allow users to access both the private IP (192.168.0.1/2/5) and the public address resolving from vpn.ourdomain.com.&amp;nbsp; When I'm at my home computer, I can resolve the name entry fine, but I cannot access the portal web page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking I have to configure the public IP on the firewall cluster, but I've no idea how to do that.&amp;nbsp; Anytime I go into Cluster Object &amp;gt; NAT &amp;gt; Advanced &amp;amp; tell it to statically xlate to the public IP address, I get a verification error saying&amp;nbsp;the cluster&amp;nbsp;cannot xlate its own address.&lt;/P&gt;&lt;P&gt;I've tried static NAT rules up the wazoo but nothing seems to be working.&amp;nbsp; I'm hoping that we don't have to change the bonded VIP to a public address b/c we'd have to rework our connection btw the firewall and edge router &amp;amp; burn some IPs, but if that's what we have to do then I guess we do have a maintenance window coming up...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&amp;nbsp; I'm sure I'm missing something stupid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, first real use and post to Checkmates so I'm excited there's this community here!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 18:25:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20512#M13699</guid>
      <dc:creator>Joshua_Snider</dc:creator>
      <dc:date>2018-05-01T18:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SNX on Cluster</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20513#M13700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any chance the border router can perform the public &amp;gt; private NAT?&lt;/P&gt;&lt;P&gt;That seems like it might be the cleanest solution here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 19:22:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20513#M13700</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-01T19:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SNX on Cluster</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20514#M13701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll give that a try, thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2018 19:53:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20514#M13701</guid>
      <dc:creator>Joshua_Snider</dc:creator>
      <dc:date>2018-05-01T19:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enable SNX on Cluster</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20515#M13702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Performing NAT on the edge router worked, thanks for the suggestion!&amp;nbsp; Wish we could've done it on the f/w so that the config for mobile access isn't spread out so much, but c'est la vie&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2018 15:29:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enable-SNX-on-Cluster/m-p/20515#M13702</guid>
      <dc:creator>Joshua_Snider</dc:creator>
      <dc:date>2018-05-18T15:29:38Z</dc:date>
    </item>
  </channel>
</rss>

