<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split Tunnel Domain group in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243023#M2304</link>
    <description>&lt;P&gt;Just do how&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp; did it. I did it same way and it worked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 05 Mar 2025 00:35:26 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-03-05T00:35:26Z</dc:date>
    <item>
      <title>Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242943#M2292</link>
      <description>&lt;P&gt;Hey folks. Wondering if anyone has gotten this working yet, and are using it in a production environment?&amp;nbsp; I've tried following the instructions laid out in this document;&amp;nbsp; &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm&lt;/A&gt;&amp;nbsp;, but when I attempt to add the domain group to the VPN group, I get&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29786i9FEA888048330501/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error.JPG" alt="error.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've got a call open with TAC, thought I'd post it here as well just in case anyone had any ideas while TAC gets around to looking at it. Running R81.20.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242943#M2292</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T16:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242950#M2293</link>
      <description>&lt;P&gt;Can you send a screenshot of what it looks like at the moment?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242950#M2293</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T16:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242951#M2294</link>
      <description>&lt;P&gt;I can easily test it in R81.20 and R82 to see if any difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242951#M2294</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T16:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242956#M2295</link>
      <description>&lt;P&gt;What does your group look like? It did not give me any fuss in R81.20 JHF 89.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupExample.png" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29787i3A8688EC573AA09D/image-size/large?v=v2&amp;amp;px=999" role="button" title="GroupExample.png" alt="GroupExample.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242956#M2295</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-04T16:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242958#M2296</link>
      <description>&lt;P&gt;Yep, I tested the same, worked fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242958#M2296</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T17:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242964#M2297</link>
      <description>&lt;P&gt;Strange indeed, here is mine&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error2.JPG" style="width: 345px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29788i88D9DDAF8E02BBAC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error2.JPG" alt="error2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:24:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242964#M2297</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T17:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242966#M2298</link>
      <description>&lt;P&gt;Just accept it and see if policy works.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:27:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242966#M2298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T17:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242990#M2299</link>
      <description>&lt;P&gt;Fails immediately.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eror3.JPG" style="width: 223px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29791i5A117436BEDF3E4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="eror3.JPG" alt="eror3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 20:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242990#M2299</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T20:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242996#M2300</link>
      <description>&lt;P&gt;The names of groups don't line up between your screenshot and the validation error, so I feel like I'm missing something.&lt;/P&gt;
&lt;P&gt;Are you nesting the earlier "VPN" group under the "Encryption.Domain" referenced in the validation error?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:25:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242996#M2300</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-04T21:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242997#M2301</link>
      <description>&lt;P&gt;Make sure group you are adding has name exclusions_&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242997#M2301</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T21:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243014#M2302</link>
      <description>&lt;P&gt;What EXACTLY are you configuring as your RemoteAccess encryption domain?&lt;BR /&gt;This should be a group object that includes the&amp;nbsp;exclusions_ group you've created.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243014#M2302</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-05T00:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243022#M2303</link>
      <description>&lt;P&gt;The Remote Access encryption domain is a group with exclusions;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ED.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29795iC6C21E6897831785/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ED.JPG" alt="ED.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This group looks as follows;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29796i608A7BAADFE77F08/image-size/medium?v=v2&amp;amp;px=400" role="button" title="group.JPG" alt="group.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the main group (non excluded) looks like this;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group2.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29797i707F7F44ED65CF86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="group2.JPG" alt="group2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243022#M2303</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T00:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243023#M2304</link>
      <description>&lt;P&gt;Just do how&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp; did it. I did it same way and it worked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:35:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243023#M2304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-05T00:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243024#M2305</link>
      <description>&lt;P&gt;See screenshots below.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:36:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243024#M2305</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T00:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243066#M2306</link>
      <description>&lt;P&gt;The problem is that's how we do traditional IP based split tunneling, which I don't want to break.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 12:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243066#M2306</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T12:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243074#M2307</link>
      <description>&lt;P&gt;You can leave the gateway encryption domain as is.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Make a new group that has all the IP addresses in it for RemoteAccess that you want&lt;/LI&gt;
&lt;LI&gt;Add the exclusions_ group to that&lt;/LI&gt;
&lt;LI&gt;Use the granular encryption domain for the RemoteAccess community&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This will only effect stuff using that RemoteAccess community.&lt;/P&gt;
&lt;P&gt;You could just clone the group you are using already and just remove the objects you are doing the exclude on.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1.png" style="width: 735px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29810i5714B9BFF542A69F/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN1.png" alt="VPN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN2.png" style="width: 542px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29811i08340F96E9F2B870/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN2.png" alt="VPN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 13:59:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243074#M2307</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-05T13:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243123#M2308</link>
      <description>&lt;P&gt;So what's the difference between these two settings? I always thought they did the same thing;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error3.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29823iDB6751F5FB3BC9B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error3.JPG" alt="error3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error5.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29824iF45917E012D4E7E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error5.JPG" alt="error5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 20:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243123#M2308</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T20:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243127#M2309</link>
      <description>&lt;P&gt;I am using my screenshot below for reference.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Section 1 - This is the default VPN domain for the gateway. RemoteAccess VPNs and IPsec VPNs will use this by default. It is a shared pool.&lt;/LI&gt;
&lt;LI&gt;Section 2 - This is where you can create a more specific VPN domain for that IPsec VPN or RemoteAccess VPN. I highlighted objects that say, "According to the gateway", that means those VPNs use the encryption domain from section 1. Everything else is using their own specific group with a much more defined encryption domain.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_Domains.png" style="width: 765px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29825i554EF7C955BF1EAE/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN_Domains.png" alt="VPN_Domains.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your new screenshots, you should just be able to add your "exclusions_" group to the group "VPN_Exclusion_Domain".&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 21:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243127#M2309</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-05T21:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243133#M2310</link>
      <description>&lt;P&gt;Thats exactly how I tested it as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 02:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243133#M2310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-06T02:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243208#M2311</link>
      <description>&lt;P&gt;Dynamic Split Tunneling requires using Hub Mode, which will break&amp;nbsp;your existing Split Tunneling configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 23:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243208#M2311</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-06T23:51:38Z</dc:date>
    </item>
  </channel>
</rss>

