<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different configs for different VPN groups? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252675#M1804</link>
    <description>&lt;P&gt;Morning,&lt;/P&gt;
&lt;P&gt;I ran across that article also and yes is exactly what I was looking for, thanks!&amp;nbsp; My plan is to have like a ttm_vendor group which will have our regular full-vpn settings and then the&amp;nbsp;&lt;SPAN&gt;trac_client_1.ttm will have the "split_tunnel" configuration and set to "true".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The only thing I'm not clear on is if we can use our existing vpn groups.&amp;nbsp; Say I have a VPN-VENDOR AD group, can it be part of the TTM_VENDOR group and get applied correctly or membership must be direct?&amp;nbsp; Will test it but in case someone knows off hand.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jul 2025 13:16:48 GMT</pubDate>
    <dc:creator>VikingsFan</dc:creator>
    <dc:date>2025-07-07T13:16:48Z</dc:date>
    <item>
      <title>Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252563#M1802</link>
      <description>&lt;P&gt;I can't find where I saw it one time and may be thinking of a different file but is there a way to push different&amp;nbsp;trac_client_1.ttm configs depending on the VPN group they're in?&amp;nbsp; Use case is we're checking out dynamic split vpn tunneling and I'm thinking about pushing different&amp;nbsp;trac_client_1.ttm files to turn on/off the split tunnel flag depending on their group.&lt;/P&gt;
&lt;P&gt;Maybe it was a different file related to VPN but I thought it was something like adding a _GROUPNAME after the file and it would load depending on their group.&amp;nbsp; Am I thinking of a different file and is there any documentation on this?&amp;nbsp; So far can't find what I'm thinking of.&lt;/P&gt;
&lt;P&gt;This is the split tunnel doc we're following:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 14:19:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252563#M1802</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-03T14:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252645#M1803</link>
      <description>&lt;P&gt;Hi VikingsFan,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might want to look at the sk114882. The setting that you are looking for is "neo_route_all_traffic_through_gateway" in the ttm file.&lt;!--  notionvc: d9c509cf-7912-4513-ad79-d9056beb5640  --&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 03:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252645#M1803</guid>
      <dc:creator>Khairulanam</dc:creator>
      <dc:date>2025-07-07T03:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252675#M1804</link>
      <description>&lt;P&gt;Morning,&lt;/P&gt;
&lt;P&gt;I ran across that article also and yes is exactly what I was looking for, thanks!&amp;nbsp; My plan is to have like a ttm_vendor group which will have our regular full-vpn settings and then the&amp;nbsp;&lt;SPAN&gt;trac_client_1.ttm will have the "split_tunnel" configuration and set to "true".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The only thing I'm not clear on is if we can use our existing vpn groups.&amp;nbsp; Say I have a VPN-VENDOR AD group, can it be part of the TTM_VENDOR group and get applied correctly or membership must be direct?&amp;nbsp; Will test it but in case someone knows off hand.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:16:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252675#M1804</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-07T13:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252677#M1805</link>
      <description>&lt;P&gt;Yes, you can. Just make sure the group name starts with "ttm_", in your case, ttm_VENDOR. I haven't tried configuring the ttm with capital letters, though, but you may try and see if it still works.&lt;/P&gt;&lt;P&gt;In my opinion, since you already have an existing VPN-VENDOR group, why don't you rename it with the new name instead of creating a new group? It will be much easier since you do not need to add any new policy for that new group.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:39:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252677#M1805</guid>
      <dc:creator>Khairulanam</dc:creator>
      <dc:date>2025-07-07T13:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252681#M1806</link>
      <description>&lt;P&gt;There are processes and other things tied to the existing AD group names.&amp;nbsp; Not being super familiar with it but what about the screenshot below?&amp;nbsp; Can I have the Check Point LDAP group named properly but it points to my actual AD group name?&amp;nbsp; So I can keep my existing naming convention in AD but it will match for the TTM name?&lt;/P&gt;
&lt;DIV id="tinyMceEditor_6adced239e4a8aVikingsFan_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-07-07_09-54-06.jpg" style="width: 427px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30904i2610D2CA84C9DAD0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2025-07-07_09-54-06.jpg" alt="2025-07-07_09-54-06.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252681#M1806</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-07T13:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252694#M1807</link>
      <description>&lt;P&gt;It does appear that creating the ttm_vendor group and pointing it to a different AD group name will work.&amp;nbsp; I'm having issues having the settings stay consistent though... for example, I switched the vendor.ttm file back to split_tunnel = false and in the client logs it keeps saying the gateway is configured to true.&amp;nbsp; Is there a trick for getting the gateway to reread the file or consistently have the changes reflect?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252694#M1807</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-07T17:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252696#M1808</link>
      <description>&lt;P&gt;As far as I know, TTM settings won't update on the client until the client disconnects and reconnects to the server.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252696#M1808</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-07T17:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252697#M1809</link>
      <description>&lt;P&gt;Thanks PhoneBoy.&amp;nbsp; I've done it multiple times with no change on the client side.&amp;nbsp; Reading the 'trac.log' file for changes but also running 'netstat -rn' shows the split tunneling even though I have it set to false (in both TTM files right now).&amp;nbsp; Even tried shutting the client down completely and reconnecting with no change.&amp;nbsp; I'm updating to R81.20 JHF 105 right now for fun and see if that changes anything.&lt;/P&gt;
&lt;P&gt;Guessing a ticket might be in order if this is not expected behaviour.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252697#M1809</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-07T17:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252699#M1810</link>
      <description>&lt;P&gt;If you make any changes to a TTM file, you must&amp;nbsp;install the Access Policy for it to take effect.&lt;BR /&gt;This is documented here: &lt;A href="https://support.checkpoint.com/results/sk/sk75221" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk75221&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 17:42:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252699#M1810</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-07T17:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252703#M1811</link>
      <description>&lt;P&gt;Yep, I've installed policy multiple times with no change.&amp;nbsp; I even check the 'do not use install policy acceleration for all targets.'&amp;nbsp; I'll keep checking.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252703#M1811</guid>
      <dc:creator>VikingsFan</dc:creator>
      <dc:date>2025-07-07T18:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Different configs for different VPN groups?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252705#M1812</link>
      <description>&lt;P&gt;That may only apply for the "main" TTM file (not the group-specific ones).&lt;BR /&gt;One other thing to try: after making the changes, try checking the file with&amp;nbsp;&lt;SPAN&gt;vpn check_ttm.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Otherwise, you're probably in TAC case territory.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 18:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Different-configs-for-different-VPN-groups/m-p/252705#M1812</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-07T18:32:36Z</dc:date>
    </item>
  </channel>
</rss>

