<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split Tunnel Domain group in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/244583#M2317</link>
    <description>&lt;P&gt;TAC got back to me on Friday, and they say that Hub Mode isn't required for this to work, the problem seems to be the Group With Exclusions, rather than it being just a simple group. I've got another call with them later today, but I'm wondering if I could just add my normal IP exclusions to this new exclusions&lt;SPAN&gt;_ group, along with my domain objects? I tried it in my lab, and it didn't give me any validation errors, but I don't have any way to actually test the VPN connectivity in my lab in order to see what it shows in the clients routing table.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Mar 2025 13:13:53 GMT</pubDate>
    <dc:creator>cdooer</dc:creator>
    <dc:date>2025-03-24T13:13:53Z</dc:date>
    <item>
      <title>Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242943#M2292</link>
      <description>&lt;P&gt;Hey folks. Wondering if anyone has gotten this working yet, and are using it in a production environment?&amp;nbsp; I've tried following the instructions laid out in this document;&amp;nbsp; &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm&lt;/A&gt;&amp;nbsp;, but when I attempt to add the domain group to the VPN group, I get&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29786i9FEA888048330501/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error.JPG" alt="error.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I've got a call open with TAC, thought I'd post it here as well just in case anyone had any ideas while TAC gets around to looking at it. Running R81.20.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:22:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242943#M2292</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T16:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242950#M2293</link>
      <description>&lt;P&gt;Can you send a screenshot of what it looks like at the moment?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242950#M2293</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T16:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242951#M2294</link>
      <description>&lt;P&gt;I can easily test it in R81.20 and R82 to see if any difference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242951#M2294</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T16:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242956#M2295</link>
      <description>&lt;P&gt;What does your group look like? It did not give me any fuss in R81.20 JHF 89.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupExample.png" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29787i3A8688EC573AA09D/image-size/large?v=v2&amp;amp;px=999" role="button" title="GroupExample.png" alt="GroupExample.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 16:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242956#M2295</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-04T16:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242958#M2296</link>
      <description>&lt;P&gt;Yep, I tested the same, worked fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:01:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242958#M2296</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T17:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242964#M2297</link>
      <description>&lt;P&gt;Strange indeed, here is mine&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error2.JPG" style="width: 345px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29788i88D9DDAF8E02BBAC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error2.JPG" alt="error2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:24:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242964#M2297</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T17:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242966#M2298</link>
      <description>&lt;P&gt;Just accept it and see if policy works.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 17:27:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242966#M2298</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T17:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242990#M2299</link>
      <description>&lt;P&gt;Fails immediately.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eror3.JPG" style="width: 223px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29791i5A117436BEDF3E4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="eror3.JPG" alt="eror3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 20:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242990#M2299</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-04T20:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242996#M2300</link>
      <description>&lt;P&gt;The names of groups don't line up between your screenshot and the validation error, so I feel like I'm missing something.&lt;/P&gt;
&lt;P&gt;Are you nesting the earlier "VPN" group under the "Encryption.Domain" referenced in the validation error?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:25:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242996#M2300</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-04T21:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242997#M2301</link>
      <description>&lt;P&gt;Make sure group you are adding has name exclusions_&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/242997#M2301</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-04T21:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243014#M2302</link>
      <description>&lt;P&gt;What EXACTLY are you configuring as your RemoteAccess encryption domain?&lt;BR /&gt;This should be a group object that includes the&amp;nbsp;exclusions_ group you've created.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:03:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243014#M2302</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-05T00:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243022#M2303</link>
      <description>&lt;P&gt;The Remote Access encryption domain is a group with exclusions;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ED.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29795iC6C21E6897831785/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ED.JPG" alt="ED.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This group looks as follows;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29796i608A7BAADFE77F08/image-size/medium?v=v2&amp;amp;px=400" role="button" title="group.JPG" alt="group.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And the main group (non excluded) looks like this;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group2.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29797i707F7F44ED65CF86/image-size/medium?v=v2&amp;amp;px=400" role="button" title="group2.JPG" alt="group2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:24:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243022#M2303</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T00:24:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243023#M2304</link>
      <description>&lt;P&gt;Just do how&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp; did it. I did it same way and it worked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:35:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243023#M2304</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-05T00:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243024#M2305</link>
      <description>&lt;P&gt;See screenshots below.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:36:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243024#M2305</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T00:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243066#M2306</link>
      <description>&lt;P&gt;The problem is that's how we do traditional IP based split tunneling, which I don't want to break.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 12:51:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243066#M2306</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T12:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243074#M2307</link>
      <description>&lt;P&gt;You can leave the gateway encryption domain as is.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Make a new group that has all the IP addresses in it for RemoteAccess that you want&lt;/LI&gt;
&lt;LI&gt;Add the exclusions_ group to that&lt;/LI&gt;
&lt;LI&gt;Use the granular encryption domain for the RemoteAccess community&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This will only effect stuff using that RemoteAccess community.&lt;/P&gt;
&lt;P&gt;You could just clone the group you are using already and just remove the objects you are doing the exclude on.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1.png" style="width: 735px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29810i5714B9BFF542A69F/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN1.png" alt="VPN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN2.png" style="width: 542px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29811i08340F96E9F2B870/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN2.png" alt="VPN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 13:59:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243074#M2307</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-05T13:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243123#M2308</link>
      <description>&lt;P&gt;So what's the difference between these two settings? I always thought they did the same thing;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error3.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29823iDB6751F5FB3BC9B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error3.JPG" alt="error3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error5.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29824iF45917E012D4E7E0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="error5.JPG" alt="error5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 20:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243123#M2308</guid>
      <dc:creator>cdooer</dc:creator>
      <dc:date>2025-03-05T20:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243127#M2309</link>
      <description>&lt;P&gt;I am using my screenshot below for reference.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Section 1 - This is the default VPN domain for the gateway. RemoteAccess VPNs and IPsec VPNs will use this by default. It is a shared pool.&lt;/LI&gt;
&lt;LI&gt;Section 2 - This is where you can create a more specific VPN domain for that IPsec VPN or RemoteAccess VPN. I highlighted objects that say, "According to the gateway", that means those VPNs use the encryption domain from section 1. Everything else is using their own specific group with a much more defined encryption domain.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_Domains.png" style="width: 765px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29825i554EF7C955BF1EAE/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN_Domains.png" alt="VPN_Domains.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your new screenshots, you should just be able to add your "exclusions_" group to the group "VPN_Exclusion_Domain".&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 21:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243127#M2309</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-03-05T21:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243133#M2310</link>
      <description>&lt;P&gt;Thats exactly how I tested it as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 02:21:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243133#M2310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-06T02:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel Domain group</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243208#M2311</link>
      <description>&lt;P&gt;Dynamic Split Tunneling requires using Hub Mode, which will break&amp;nbsp;your existing Split Tunneling configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 23:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-Domain-group/m-p/243208#M2311</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-06T23:51:38Z</dc:date>
    </item>
  </channel>
</rss>

