<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: temporary disable remote access in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229208#M3091</link>
    <description>&lt;P&gt;HTTPS isn't needed for S2S VPN so it can be safely blocked.&lt;BR /&gt;If you have remote VPN peers with fixed IPs, you can block NAT-T from other hosts (temporarily) to effectively "disable" Remote Access using&amp;nbsp;fwaccel dos commands.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Oct 2024 19:51:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-08T19:51:18Z</dc:date>
    <item>
      <title>temporary disable remote access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229173#M3088</link>
      <description>&lt;P&gt;For a migration test we are looking for a way to disable quick and temporary remote access on a gateway and get it back enable as fast as possible.&lt;/P&gt;
&lt;P&gt;We are using the Endpoint VPN client only to connect to the gateway, no SNX.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Blocking access to the gateway for NAT-T and HTTPs with a firewall in front of the gateway does work. But we have some site2site VPNs using NAT-T and they are blocked, which we not want.&lt;/P&gt;
&lt;P&gt;Removing the gateway from the remote access community is a solutions but this has to much impact of the configuration, we don't want.&lt;/P&gt;
&lt;P&gt;Any other ways to disable or block or anything else like stopping a service to disable the remote access temporary?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 12:04:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229173#M3088</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-10-08T12:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: temporary disable remote access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229177#M3089</link>
      <description>&lt;P&gt;I do not think so - looking through &lt;A href="https://support.checkpoint.com/results/sk/sk97638" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk97638&lt;/A&gt; all possibilities to stop processes for RA VPN will also affect S2S VPN...&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 12:23:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229177#M3089</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-10-08T12:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: temporary disable remote access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229178#M3090</link>
      <description>&lt;P&gt;You could add a top layer with the office mode network allowed by default and blocked when you need it, followed by any/any/accept to your main layer.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 12:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229178#M3090</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-10-08T12:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: temporary disable remote access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229208#M3091</link>
      <description>&lt;P&gt;HTTPS isn't needed for S2S VPN so it can be safely blocked.&lt;BR /&gt;If you have remote VPN peers with fixed IPs, you can block NAT-T from other hosts (temporarily) to effectively "disable" Remote Access using&amp;nbsp;fwaccel dos commands.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 19:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229208#M3091</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-08T19:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: temporary disable remote access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229340#M3092</link>
      <description>&lt;P&gt;Just to inform....blocking HTTPS from any to our RemoteAccess-gateway via the firewall-gateway in front does the job. No need to block NAT-T.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 07:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/temporary-disable-remote-access/m-p/229340#M3092</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2024-10-10T07:19:54Z</dc:date>
    </item>
  </channel>
</rss>

