<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to exclude a network or host form split tunnel in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/275638#M14453</link>
    <description>&lt;P&gt;Late to the party, but take 122 is where we added the ability to do inclusions for dynamic objects. Prior to this only exclusions were allowed. The difference is when using hub mode, you want to exclude dynamic objects to allow them to go direct to the Internet versus when already using split tunnel (only sending encryption domain across tunnel) but want to add dynamic sites that need to be routed through the RA VPN.&lt;/P&gt;
&lt;P&gt;The include is probably most useful when third-party vendors whitelist the IP that is allowed to access a resource. This allows you to force their domain down the RA VPN so the RA users end up using your external (whitelisted) IP.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2026 16:37:39 GMT</pubDate>
    <dc:creator>CP_Chris</dc:creator>
    <dc:date>2026-04-16T16:37:39Z</dc:date>
    <item>
      <title>How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267186#M1350</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Mates!!&lt;BR /&gt;&lt;BR /&gt;Can anyone help me to understand, How I can exclude a network from Check Point split tunneling?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 12:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267186#M1350</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-01-13T12:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267191#M1351</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;See if below helps.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Domain-objects-in-remote-access-vpn-domain/m-p/246249#M12365" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Domain-objects-in-remote-access-vpn-domain/m-p/246249#M12365&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 12:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267191#M1351</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-13T12:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267194#M1352</link>
      <description>&lt;P&gt;based on the documentation:&lt;BR /&gt;&lt;SPAN class="Important_Note"&gt;Note:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Starting&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm" target="_blank" rel="noopener"&gt;R81.20 Jumbo Hotfix Accumulator&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;Take 122 you can add host/network/range objects for split tunnel on exclusion/inclusion modes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;i can exclude network only from 122? right?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267194#M1352</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-01-13T13:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267195#M1353</link>
      <description>&lt;P&gt;I am fairly sure I had done that for a client thats on way lower jumbo on R81.20&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:05:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267195#M1353</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-13T13:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267196#M1354</link>
      <description>&lt;P&gt;Idk brother..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Important_Note"&gt;Important&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Naming is critical – the system uses this prefix to identify the mode.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The group must directly contain&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Important_Note"&gt;only&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;these object types:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Updatable objects&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Dynamic objects&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Domain objects&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Nested groups are not supported, even if the nested group contains only allowed object types.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Important_Note"&gt;Note:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Starting&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm" target="_blank" rel="noopener"&gt;R81.20 Jumbo Hotfix Accumulator&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Take 122 you can add host/network/range objects for split tunnel on exclusion/inclusion modes.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267196#M1354</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-01-13T13:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267197#M1355</link>
      <description>&lt;P&gt;Thats right...IT HAS TO START with exclusions_&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:10:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267197#M1355</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-13T13:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267198#M1356</link>
      <description>&lt;P&gt;yeah i know about that but i asking if it start from 122, but if you told me that you've alreday do that in lower version i trust you&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267198#M1356</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-01-13T13:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267201#M1357</link>
      <description>&lt;P&gt;I just checked my notes and I see my colleague and I did this for a client on R81.20 jumbo 99&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:19:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267201#M1357</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-13T13:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267202#M1358</link>
      <description>&lt;P&gt;thank you brother i'll try&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267202#M1358</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-01-13T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267203#M1359</link>
      <description>&lt;P&gt;Sure! Let us know how it goes.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 13:21:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/267203#M1359</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-13T13:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude a network or host form split tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/275638#M14453</link>
      <description>&lt;P&gt;Late to the party, but take 122 is where we added the ability to do inclusions for dynamic objects. Prior to this only exclusions were allowed. The difference is when using hub mode, you want to exclude dynamic objects to allow them to go direct to the Internet versus when already using split tunnel (only sending encryption domain across tunnel) but want to add dynamic sites that need to be routed through the RA VPN.&lt;/P&gt;
&lt;P&gt;The include is probably most useful when third-party vendors whitelist the IP that is allowed to access a resource. This allows you to force their domain down the RA VPN so the RA users end up using your external (whitelisted) IP.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2026 16:37:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-exclude-a-network-or-host-form-split-tunnel/m-p/275638#M14453</guid>
      <dc:creator>CP_Chris</dc:creator>
      <dc:date>2026-04-16T16:37:39Z</dc:date>
    </item>
  </channel>
</rss>

