<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Route VPN client remote access to LAN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7499#M14271</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have some troubles with remote access client VPN.&lt;BR /&gt;With office mode, client behind ISP is on the same subnet that LAN. VPN connexion is OK but the problem is when there are device behind ISP who has the same IP address than another device behind the firewall on the LAN. can someone help us please. Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appliance 4800&lt;/P&gt;&lt;P&gt;R77.10&lt;/P&gt;&lt;P&gt;LAN &amp;gt;&amp;gt; 192.168.1.0/24&lt;/P&gt;&lt;P&gt;Office mode subnet &amp;gt;&amp;gt; 10.8.10.0/24&lt;/P&gt;&lt;P&gt;Remote client subnet behind ISP &amp;gt;&amp;gt; Same that LAN 192.168.1.0/24&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Oct 2017 07:52:13 GMT</pubDate>
    <dc:creator>Administrateur_</dc:creator>
    <dc:date>2017-10-16T07:52:13Z</dc:date>
    <item>
      <title>Route VPN client remote access to LAN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7499#M14271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have some troubles with remote access client VPN.&lt;BR /&gt;With office mode, client behind ISP is on the same subnet that LAN. VPN connexion is OK but the problem is when there are device behind ISP who has the same IP address than another device behind the firewall on the LAN. can someone help us please. Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appliance 4800&lt;/P&gt;&lt;P&gt;R77.10&lt;/P&gt;&lt;P&gt;LAN &amp;gt;&amp;gt; 192.168.1.0/24&lt;/P&gt;&lt;P&gt;Office mode subnet &amp;gt;&amp;gt; 10.8.10.0/24&lt;/P&gt;&lt;P&gt;Remote client subnet behind ISP &amp;gt;&amp;gt; Same that LAN 192.168.1.0/24&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 07:52:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7499#M14271</guid>
      <dc:creator>Administrateur_</dc:creator>
      <dc:date>2017-10-16T07:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN client remote access to LAN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7500#M14272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OfficeMode should solve your issue having the same IP/network on both sides.&lt;/P&gt;&lt;P&gt;First, please check your firewall log for any spoofing entries. If these are logged, try to exclude your OfficeMode network from the address spoofing configuration of your external interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check that the OfficeMode IP is correctly applied to your remote client. You can check this within the VPN client's connection settings while the VPN tunnel is establied and also on the client's cmd via ipconfig.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check if a Desktop Policy is in place that might prevent specific traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:23:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7500#M14272</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2017-10-16T09:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN client remote access to LAN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7501#M14273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Danny Jung,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to exclude OfficeMode network from the address spoofing configuration of our external interface. still have the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We dont have Desktop Policy.&lt;BR /&gt;This is VPN client connection settings:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/60120_Administrateur&amp;nbsp;_ Windows PowerShell 16_10_2017 11_35_11.png" style="width: 620px; height: 404px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7501#M14273</guid>
      <dc:creator>Administrateur_</dc:creator>
      <dc:date>2017-10-16T09:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN client remote access to LAN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7502#M14274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We connect with VPN capsule on Windows 10 and still cannot ping device in the LAN behind the firewall because there is same IP address behind ISP. We try to connect with endpoint and it works. Why this does not work witch capsule ??. can someone help us please?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Oct 2017 22:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7502#M14274</guid>
      <dc:creator>Administrateur_</dc:creator>
      <dc:date>2017-10-16T22:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN client remote access to LAN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7503#M14275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are always going to have a bad time if your local client is using an IP address that is also used by the remote VPN.&lt;/P&gt;&lt;P&gt;I had a similar problem years ago when the VPN was preventing me from using my local LAN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ended up writing a batch file to solve the problem, which, with some modifications, may be useful.&lt;/P&gt;&lt;P&gt;Note that this also starts up SecuRemote in CLI mode, which may not work or be relevant anymore.&lt;/P&gt;&lt;P&gt;From&amp;nbsp;&lt;A class="link-titled" href="https://phoneboy.com/1405/fun-with-check-point-secureclient-and-windows-batch-files" title="https://phoneboy.com/1405/fun-with-check-point-secureclient-and-windows-batch-files"&gt;https://phoneboy.com/1405/fun-with-check-point-secureclient-and-windows-batch-files&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="color: #999999; background-color: #f8f8f8; border: 1px solid #cccccc; font-weight: 300; margin: 15px 0px; padding: 6px 10px;"&gt;@REM kill Echo @echo off setlocal EnableDelayedExpansion&lt;BR /&gt;set SCC="C:Program Files\\CheckPoint\\SecuRemote\\bin\\scc"&lt;BR /&gt;%SCC% setmode cli&lt;BR /&gt;rem %SCC% disconnect&lt;BR /&gt;%SCC% up username %1%&lt;BR /&gt;%SCC% connect "VPN Profile"&lt;BR /&gt;%SCC% status&lt;BR /&gt;%SCC% ep&lt;BR /&gt;@REM Trying to pull out VPN route and mess with routing table&lt;BR /&gt;@REM&lt;BR /&gt;@REM Did we find the netmask line?&lt;BR /&gt;set hitnetmask=0&lt;BR /&gt;@REM Let's pull out a route I know will be there:&lt;BR /&gt;&lt;BR /&gt;@for /f "tokens=3" %%i in ('route print 192.168.0.0') do (&lt;BR /&gt;&lt;BR /&gt;@REM After we found the netmask, the next thing we get is the route we want&lt;BR /&gt;@REM and make sure we get out of dodge&lt;BR /&gt;if !hitnetmask! EQU 1 (&lt;BR /&gt;call :set_nexthop %%i&lt;BR /&gt;GOTO :found_route&lt;BR /&gt;)&lt;BR /&gt;@REM The next line after the "netmask" line is the one we want.&lt;BR /&gt;if "%%i" == "Netmask" (call :set_hitnetmask)&lt;BR /&gt;&lt;BR /&gt;@REM end for&lt;BR /&gt;)&lt;BR /&gt;&lt;BR /&gt;:set_hitnetmask&lt;BR /&gt;set hitnetmask=1&lt;BR /&gt;GOTO :EOF&lt;BR /&gt;&lt;BR /&gt;:set_nexthop&lt;BR /&gt;set nexthop=%1&lt;BR /&gt;GOTO :EOF&lt;BR /&gt;&lt;BR /&gt;:found_route&lt;BR /&gt;echo Nexthop is %nexthop%, deleting/setting the routes appropriately&lt;BR /&gt;echo on&lt;BR /&gt;route delete 192.168.0.0 mask 255.255.255.0 %nexthop%&lt;BR /&gt;route delete 192.168.0.2 %nexthop%&lt;BR /&gt;route delete 192.168.2.253 %nexthop%&lt;BR /&gt;route add 192.168.2.253 192.168.0.254&lt;BR /&gt;@endlocal&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Oct 2017 01:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-client-remote-access-to-LAN/m-p/7503#M14275</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-10-17T01:09:35Z</dc:date>
    </item>
  </channel>
</rss>

