<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LAN‑Initiated Connections to Remote Access VPN Clients (Office Mode IP) Not Working in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/LAN-Initiated-Connections-to-Remote-Access-VPN-Clients-Office/m-p/276231#M14473</link>
    <description>&lt;P&gt;Have you accounted for things like the default automatic NAT that is applied to the office mode address pool object &amp;amp; anti-spoofing etc?&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2026 09:09:37 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2026-04-29T09:09:37Z</dc:date>
    <item>
      <title>LAN‑Initiated Connections to Remote Access VPN Clients (Office Mode IP) Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/LAN-Initiated-Connections-to-Remote-Access-VPN-Clients-Office/m-p/276224#M14472</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are unable to establish LAN‑initiated connections to Remote Access VPN clients using Office Mode IPs. ICMP traffic from LAN to remote users is accepted and encrypted in the RemoteAccess community, but there is no reply from the remote users back to the LAN.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In SmartConsole we configured rules to allow traffic from the LAN server to the Office Mode IP pool, and logs confirm the traffic is encrypted and allowed. We also enabled “Enable Back Connections” in Global Properties, but the outcome remains the same. Disabling the internal firewall on the remote client did not resolve the issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has anyone successfully configured LAN‑to‑Remote Access back connections? Is there a recommended Access Policy setup or directional match condition that allows LAN hosts to initiate traffic toward Office Mode clients while maintaining proper VPN enforcement?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 05:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/LAN-Initiated-Connections-to-Remote-Access-VPN-Clients-Office/m-p/276224#M14472</guid>
      <dc:creator>DominusRex23</dc:creator>
      <dc:date>2026-04-29T05:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: LAN‑Initiated Connections to Remote Access VPN Clients (Office Mode IP) Not Working</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/LAN-Initiated-Connections-to-Remote-Access-VPN-Clients-Office/m-p/276231#M14473</link>
      <description>&lt;P&gt;Have you accounted for things like the default automatic NAT that is applied to the office mode address pool object &amp;amp; anti-spoofing etc?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 09:09:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/LAN-Initiated-Connections-to-Remote-Access-VPN-Clients-Office/m-p/276231#M14473</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-29T09:09:37Z</dc:date>
    </item>
  </channel>
</rss>

