<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different Routes for Remote VPN clients in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261154#M1535</link>
    <description>&lt;P&gt;Yes, you will need to add the relevant subnets to the RemoteAccess Encryption Domain.&lt;BR /&gt;Whether the client has access to these subnets is a function of the defined Access Policy, but all clients will receive the routes.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Oct 2025 14:20:51 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-10-28T14:20:51Z</dc:date>
    <item>
      <title>Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261143#M1534</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have task to propagate different routes for Remote VPN clients. Is it possible?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Environment:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Checkpoint FW - R81.10 Jumbo Hotfix Take 181&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote access VPN clients Checkpoint Mobile VPN E88.10 with LDAP Authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote clients receive from Checkpoint GW&amp;nbsp; Office mode manually defined ip addresses.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Scenario:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only specific Remote VPN client should be able to reach not only local subnets but also some specific subnets which located behind s-2-s VPN tunnel in different location.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Traffic flow diagram for specific Remote VPN clients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote Client &amp;lt;-&amp;gt; Checkpoint GW (local int) &amp;lt;-&amp;gt; (local int) VPN GW &amp;lt;-&amp;gt; VPN GW &amp;lt;-&amp;gt; dst subnets.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Oct 2025 12:35:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261143#M1534</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2025-10-28T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261154#M1535</link>
      <description>&lt;P&gt;Yes, you will need to add the relevant subnets to the RemoteAccess Encryption Domain.&lt;BR /&gt;Whether the client has access to these subnets is a function of the defined Access Policy, but all clients will receive the routes.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Oct 2025 14:20:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261154#M1535</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-28T14:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261162#M1536</link>
      <description>&lt;P&gt;Dear PhoneBoy.&lt;/P&gt;&lt;P&gt;Thank you for reply but we need add subnets ONLY for specific Remote VPN clients (AD accounts).&amp;nbsp;&lt;/P&gt;&lt;P&gt;May be it will be possible via some "routing tables" config file on client side or something similar with TRAC file on FW side?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Oct 2025 15:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261162#M1536</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2025-10-28T15:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261279#M1537</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17366"&gt;@Glenmark_Impex&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not 100% sure this will be a solution, but I would like to share with you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I see you are using a VPN pool for the RA cliens IP-s.&lt;/P&gt;
&lt;P&gt;First, consider to use ipassingment.conf (&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;$FWDIR/conf/ipassignment.conf)&lt;/CODE&gt;, define a smaller network from the VPN pool for a specific AD group.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Office-Mode.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Office-Mode.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This allows you to handle the client separetly in the rulebase. "A" group reaches the internet, and the "B" not.&lt;/P&gt;
&lt;P&gt;I hope it helps,&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 11:45:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261279#M1537</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-10-29T11:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261297#M1538</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17366"&gt;@Glenmark_Impex&lt;/a&gt;&amp;nbsp;is explicitly asking about the routes received on the client.&lt;BR /&gt;Unfortunately, this is not customizable on a per-user/group basis.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Oct 2025 14:42:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261297#M1538</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-29T14:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Different Routes for Remote VPN clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261365#M1539</link>
      <description>&lt;P&gt;Hi AkosBakos&lt;/P&gt;&lt;P&gt;Sorry but no, only specific clients "should know" about destination subnets.... Also we are considering the possibility&amp;nbsp;to use MEP or just run another one Checkpoint with Remote VPN blade&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 07:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-Routes-for-Remote-VPN-clients/m-p/261365#M1539</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2025-10-30T07:44:32Z</dc:date>
    </item>
  </channel>
</rss>

