<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using same enc domain for remote access on more than one firewall in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257241#M1642</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;using the same encryption domain on multiple gateways for remote access is possible. Normally this is called and done MEP (MultipleEntryPoint). You have to have an eye for the return packets if used MEP.&lt;/P&gt;
&lt;P&gt;I don‘t know if this help for your needs, maybe you have to describe this.&lt;/P&gt;</description>
    <pubDate>Sun, 14 Sep 2025 19:20:15 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2025-09-14T19:20:15Z</dc:date>
    <item>
      <title>Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257229#M1640</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Just for my own sanity, though we already confirmed with the customer doing this caused the issue, but they were wondering if doing so, one can make it work? So essentially have SAME remote access enc domain for 2 clusters, one for on prem and one Azure?&lt;/P&gt;
&lt;P&gt;I cant really see how that would work, but just wondering if its even possible? if not, could they use same random subnets from large group already used for onprem to test Azure side or in order to use same one, it would need to be done during cutover window?&lt;/P&gt;
&lt;P&gt;Tx as always!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 12:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257229#M1640</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T12:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257239#M1641</link>
      <description>&lt;P&gt;For what is worth, I even had it configured with 2 subnets from current RA group used on prem, but even that caused an issue, so now Im really wondering how this can be tested before the actual cutover.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 18:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257239#M1641</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T18:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257241#M1642</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;using the same encryption domain on multiple gateways for remote access is possible. Normally this is called and done MEP (MultipleEntryPoint). You have to have an eye for the return packets if used MEP.&lt;/P&gt;
&lt;P&gt;I don‘t know if this help for your needs, maybe you have to describe this.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 19:20:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257241#M1642</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-09-14T19:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257242#M1643</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for that. I see what you mean, though now we have to pause on this, since we dont want to cause customer more issues, as they heavily rely on remote access. I did end up opening TAC case about it, so lets see what they say &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 20:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257242#M1643</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T20:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257245#M1644</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I assume this is the link you meant?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm#:~:text=same%20internal%20network.-,The%20Check%20Point%20Solution%20for%20Multiple%20Entry%20Points,at%20the%20same%20geographical%20site" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm#:~:text=same%20internal%20network.-,The%20Check%20Point%20Solution%20for%20Multiple%20Entry%20Points,at%20the%20same%20geographical%20site&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Sep 2025 21:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257245#M1644</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-14T21:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257255#M1645</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; yes, that's it. We have customers using this as active/backup and others using Loadbalancing to distribute the remote users between gateways. Works like a charm. With different IP-pools for office-mode on every gateway you are fine with the back routing to the endpoints. I always use some SAM rules (blocking HTTPS to the gateway) to test the failover to another gateway. With these SAM rule you can add and remove block rules quickly and you can skip the internal rules, because SAM rules are working before.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 06:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257255#M1645</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-09-15T06:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Using same enc domain for remote access on more than one firewall</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257269#M1646</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Sep 2025 10:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-same-enc-domain-for-remote-access-on-more-than-one/m-p/257269#M1646</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-15T10:15:55Z</dc:date>
    </item>
  </channel>
</rss>

