<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Always-On VPN with full traffic tunneling and split-exclusion for authentication? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Always-On-VPN-with-full-traffic-tunneling-and-split-exclusion/m-p/249132#M1978</link>
    <description>&lt;P&gt;This requires a few things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hub Mode be configured (this routes all traffic through the VPN)
&lt;UL&gt;
&lt;LI&gt;You can exclude locally connected networks from this (to allow your users to, for instance, print to their local printer):&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You can also exclude specific applications like Zoom from going through the VPN:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm?tocpath=_____19" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm?tocpath=_____19&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You can also require this only on certain firewalls:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk111995" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111995&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Endpoint Firewall (necessary to block access when disconnected from VPN). Note that this feature requires either Harmony Endpoint or CPEP-ACCESS licenses.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Location Awareness (disables VPN when certain conditions are met)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Harmony SASE also supports this configuration.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 17:11:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-05-15T17:11:08Z</dc:date>
    <item>
      <title>Always-On VPN with full traffic tunneling and split-exclusion for authentication?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Always-On-VPN-with-full-traffic-tunneling-and-split-exclusion/m-p/249120#M1977</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm looking to implement an &lt;STRONG&gt;Always-On VPN&lt;/STRONG&gt; setup using a Check Point Remote Access VPN client. The goal is to ensure that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The &lt;STRONG&gt;VPN connection is mandatory&lt;/STRONG&gt;: if the client is not connected to the VPN, it should not have access to the internet at all (no split tunneling).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;All traffic (internal and internet)&lt;/STRONG&gt; is routed through the corporate firewall when the VPN is active.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Exceptions&lt;/STRONG&gt; are made only for traffic related to authentication to the VPN gateway (e.g., DNS resolution, SAML login, etc.).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;When the device is &lt;STRONG&gt;on-site (corporate network)&lt;/STRONG&gt;, the VPN should detect it and not initiate the tunnel.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Is this kind of setup achievable?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your insights!&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 15:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Always-On-VPN-with-full-traffic-tunneling-and-split-exclusion/m-p/249120#M1977</guid>
      <dc:creator>gg_fga</dc:creator>
      <dc:date>2025-05-15T15:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Always-On VPN with full traffic tunneling and split-exclusion for authentication?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Always-On-VPN-with-full-traffic-tunneling-and-split-exclusion/m-p/249132#M1978</link>
      <description>&lt;P&gt;This requires a few things:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Hub Mode be configured (this routes all traffic through the VPN)
&lt;UL&gt;
&lt;LI&gt;You can exclude locally connected networks from this (to allow your users to, for instance, print to their local printer):&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Excluding-Local-Networks-from-Hub-Mode.htm&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You can also exclude specific applications like Zoom from going through the VPN:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm?tocpath=_____19" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm?tocpath=_____19&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;You can also require this only on certain firewalls:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk111995" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111995&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Endpoint Firewall (necessary to block access when disconnected from VPN). Note that this feature requires either Harmony Endpoint or CPEP-ACCESS licenses.&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Location Awareness (disables VPN when certain conditions are met)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Harmony SASE also supports this configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 17:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Always-On-VPN-with-full-traffic-tunneling-and-split-exclusion/m-p/249132#M1978</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-15T17:11:08Z</dc:date>
    </item>
  </channel>
</rss>

