<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic Split Tunneling in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277629#M14520</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have a checkpoint firewall operating on R82 with remote access VPN functionality activated. We have set up a Full tunnel (Hub mode) with Dynamic Split tunneling (where only a few IP addresses are excluded), utilizing the object-group: &lt;STRONG&gt;exclusions_&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Upon examining the route print on the user machine, we observed that a default route has been injected with the mask 252.0.0.0. Consequently, we encountered an issue where, for the proxy solution to recognize the VPN network, it must align with the strict default route of 0.0.0.0 with a mask of 0.0.0.0.&lt;/P&gt;&lt;P&gt;1. What steps are necessary to insert a default route with the mask 0.0.0.0?&lt;/P&gt;&lt;P&gt;2. Given that we have dynamic split tunneling enabled, could this lead to any connectivity problems?&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
    <pubDate>Sat, 30 May 2026 04:07:29 GMT</pubDate>
    <dc:creator>SriNarasimha005</dc:creator>
    <dc:date>2026-05-30T04:07:29Z</dc:date>
    <item>
      <title>Dynamic Split Tunneling</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277629#M14520</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have a checkpoint firewall operating on R82 with remote access VPN functionality activated. We have set up a Full tunnel (Hub mode) with Dynamic Split tunneling (where only a few IP addresses are excluded), utilizing the object-group: &lt;STRONG&gt;exclusions_&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Upon examining the route print on the user machine, we observed that a default route has been injected with the mask 252.0.0.0. Consequently, we encountered an issue where, for the proxy solution to recognize the VPN network, it must align with the strict default route of 0.0.0.0 with a mask of 0.0.0.0.&lt;/P&gt;&lt;P&gt;1. What steps are necessary to insert a default route with the mask 0.0.0.0?&lt;/P&gt;&lt;P&gt;2. Given that we have dynamic split tunneling enabled, could this lead to any connectivity problems?&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
      <pubDate>Sat, 30 May 2026 04:07:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277629#M14520</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-05-30T04:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Split Tunneling</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277670#M14521</link>
      <description>&lt;P&gt;Hi Gents&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you're doing well.&lt;/P&gt;&lt;P&gt;I’m currently stuck on this and need some help. Do you have a few minutes to give me your advice?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 11:41:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277670#M14521</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-06-01T11:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Split Tunneling</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277697#M14522</link>
      <description>&lt;P&gt;I don't believe we ever inject a 0.0.0.0/0.0.0.0 route into the Remote Access client, which means this is likely an &lt;A href="https://support.checkpoint.com/results/sk/sk71840" target="_self"&gt;RFE&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The only method I know for configuring the routes sent to the client is through the encryption domain or something like&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk92676" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk92676&lt;/A&gt;&amp;nbsp;which is not your use case here.&lt;BR /&gt;The only method I can think of is to set this route up AFTER connecting with the Remote Access client.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2026 18:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277697#M14522</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-01T18:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Split Tunneling</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277704#M14523</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response. The encryption domain is set to 0.0.0.0/0 with few exclusions.&lt;/P&gt;&lt;P&gt;Given that we have several VPN firewalls, implementing a static route may not be effective. Is there a possibility of altering the trac file?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 03:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277704#M14523</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-06-02T03:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Split Tunneling</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277768#M14528</link>
      <description>&lt;P&gt;Modify trac to do what, inject a 0.0.0.0/0.0.0.0 route?&lt;BR /&gt;Like I said, that's probably an &lt;A href="https://support.checkpoint.com/results/sk/sk71840" target="_blank"&gt;RFE&lt;/A&gt; (i.e. not in the product).&lt;/P&gt;
&lt;P&gt;The static route I'm referring would have to be done on the client itself.&lt;BR /&gt;Nearly 20 years ago, I actually wrote a Windows BAT file that would automate the process of creating a desired route based on what comes back from the VPN gateway:&amp;nbsp;&lt;A href="https://phoneboy.com/1405/fun-with-check-point-secureclient-and-windows-batch-files" target="_blank"&gt;https://phoneboy.com/1405/fun-with-check-point-secureclient-and-windows-batch-files&lt;/A&gt;&lt;BR /&gt;Whether this still works or not is a separate question.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 15:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Dynamic-Split-Tunneling/m-p/277768#M14528</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-02T15:40:34Z</dc:date>
    </item>
  </channel>
</rss>

