<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stuck at 47% when RA VPN from internal network in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228458#M3131</link>
    <description>&lt;P&gt;Wait a second...why do you have a need to do this INTERNALLY??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2024 13:31:36 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-30T13:31:36Z</dc:date>
    <item>
      <title>Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228172#M3126</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your attention to this matter.&lt;/P&gt;&lt;P&gt;Currently I'm unable connect Remote Access VPN from my internal network,&amp;nbsp;although when I'm tried to connect from external, at home still successfully.&lt;/P&gt;&lt;P&gt;Product: 6600 appliance&lt;BR /&gt;Version: R81.20 take 84&lt;BR /&gt;Endpoint Security version E86.50, 88.40,...&lt;/P&gt;&lt;P&gt;Connect RA VPN using NATed IP (&lt;SPAN&gt;Statically NATed by ISP-Peplink&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When connecting to RA VPN from a device in the internal network, it gets stuck at 47% "User *** authenticated by FireWall-1 authentication".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (2).png" style="width: 891px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27841i739400FBF0FE54A4/image-dimensions/891x480?v=v2" width="891" height="480" role="button" title="image (2).png" alt="image (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then failed:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (3).png" style="width: 890px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27842i0512CD75830DDDCA/image-dimensions/890x505?v=v2" width="890" height="505" role="button" title="image (3).png" alt="image (3).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Log showing no error:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image (4).png" style="width: 889px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27843i61B00DEF3763283D/image-dimensions/889x449?v=v2" width="889" height="449" role="button" title="image (4).png" alt="image (4).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Already tried:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- In Global properties &amp;gt; RA &amp;gt; Enable Back Connections (from gateway to client). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;- Set "No" at Network location awareness.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk129492" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk129492&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk156172" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk156172&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk92716" target="_self"&gt;https://support.checkpoint.com/results/sk/sk92716&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk160672" target="_self"&gt;https://support.checkpoint.com/results/sk/sk160672&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;- Open with TAC still no luck&lt;/P&gt;&lt;P&gt;When I tried to use internal interface IP for create a site to connect, it success one time only: success =&amp;gt; disconnect =&amp;gt; connected again -&amp;gt; stuck at 47% -&amp;gt; failed =&amp;gt; delete site =&amp;gt; create new again =&amp;gt; connect success =&amp;gt; ... loop&lt;/P&gt;&lt;P&gt;Note: Problem happen only connect from internal network and our policy needed to RA VPN from internal to access some server.&lt;/P&gt;&lt;P&gt;Does anyone facing this problem before, please help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much and have a great day!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Kha&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 27 Sep 2024 05:50:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228172#M3126</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-09-27T05:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228213#M3127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/106488"&gt;@Mk_83&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you dump the connection process on the RA gateway?&lt;/P&gt;
&lt;P&gt;What is under IPsec VPN -&amp;gt;Link Selection?&lt;/P&gt;
&lt;P&gt;I suppose that, when you create a VPNsite with internal address&amp;nbsp; -&amp;gt;the connection succeded for the first time -&amp;gt; at this time the client downloads the topology&amp;nbsp; -&amp;gt; because of the newly downloaded topology setting, the second try will be fail.&lt;/P&gt;
&lt;P&gt;This is my first first guess &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 15:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228213#M3127</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-27T15:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228214#M3128</link>
      <description>&lt;P&gt;Does it make any difference if you try delete/recreate the site?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:05:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228214#M3128</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-27T13:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228456#M3129</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;Akos,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I really appreciate your help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you guide me how to dump the connection process on the RA gateway?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Under IPsec VPN -&amp;gt;Link Selection -&amp;gt; Always use this IP Address -&amp;gt; Statically NATed IP: IP&amp;nbsp;NATed by ISP-Peplink (x.x.x.x).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I saw in the first time connect the log showing source from exactly IP of my device, but the second time the source is IP that connect with Checkpoint interface of Peplink (exam: checkpoint 172.16.9.8 ; peplink: 172.16.9.9). The second time try connect using internal IP, and connect using NAT IP always showing the source is 172.16.9.9. I still don't know why it redirect to that.&lt;/P&gt;&lt;P&gt;Do you have any ideals for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best Regard,&lt;/P&gt;&lt;P&gt;Kha&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228456#M3129</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-09-30T13:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228457#M3130</link>
      <description>&lt;P&gt;Hello the_rock,&lt;/P&gt;&lt;P&gt;I check and see it's not have any difference when I'm tried delete/recreate the site, the difference here when I try to connect the second time.&lt;/P&gt;&lt;P&gt;But that delete/recreate only happen when we using internal IP, if using NAT IP its couldn't connect even from the first time.&amp;nbsp;And it also doesn't make sense for us to force users to manually change their connection IP (or delete/recreate) when they work from home and at office.&lt;/P&gt;&lt;P&gt;We still want to use NAT IP to connect successfully from outside and inside the internal network.&lt;/P&gt;&lt;P&gt;Have you ever tried this problem before? Or if you have any ideals, please help us.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best Regards,&lt;/P&gt;&lt;P&gt;Kha&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:26:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228457#M3130</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-09-30T13:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228458#M3131</link>
      <description>&lt;P&gt;Wait a second...why do you have a need to do this INTERNALLY??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228458#M3131</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-30T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228466#M3132</link>
      <description>&lt;P&gt;Hello the_rock,&lt;/P&gt;&lt;P&gt;I know this is quite strange.&lt;BR /&gt;But because my company's policy has been like that since before, our environment is a school, each wifi zone will only be able to connect to its own partition, so when teachers or staff go to another wifi zone to teach/work, they sometimes need remote access from the inside because some places do not allow direct access to their resources.&lt;/P&gt;&lt;P&gt;It can be said that our network system planning is not good, but I remember that in my previous workplaces using Checkpoint, I could still VPN from the inside, so I am thinking that this is not a limitation of Checkpoint but this is a error somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best regards,&lt;/P&gt;&lt;P&gt;Kha&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:41:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228466#M3132</guid>
      <dc:creator>Mk_83</dc:creator>
      <dc:date>2024-09-30T13:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228471#M3133</link>
      <description>&lt;P&gt;Hey Kha,&lt;/P&gt;
&lt;P&gt;No, thats totally FAIR, I understand now. Sorry, was not trying to be "intrusive" about it, just wanted to make sure logic is there.&lt;/P&gt;
&lt;P&gt;Anyway, may have to do with below setting in global properties...can you see how its configured? I know clients I helped with this in the past would have their INTERNAL network listed in the group I pointed out to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27919i109DA72877CC78A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 13:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228471#M3133</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-30T13:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Stuck at 47% when RA VPN from internal network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228492#M3134</link>
      <description>&lt;P&gt;This might be what you need to here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk103440" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103440&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You would need a single FDQN in your DNS that:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Resolves externally to the NAT IP&lt;/LI&gt;
&lt;LI&gt;Resolves internally to the real IP&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 30 Sep 2024 14:47:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Stuck-at-47-when-RA-VPN-from-internal-network/m-p/228492#M3134</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-30T14:47:55Z</dc:date>
    </item>
  </channel>
</rss>

