<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split tunnel and exclude subnets in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221489#M3448</link>
    <description>&lt;P&gt;By design, when you “add new site” you get information about all VPN gateways managed by the same SMS.&lt;BR /&gt;Version/JHF level along with a diagram of what you’re trying to achieve will help tremendously.&lt;/P&gt;</description>
    <pubDate>Sun, 21 Jul 2024 15:39:30 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-21T15:39:30Z</dc:date>
    <item>
      <title>Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221481#M3447</link>
      <description>&lt;P&gt;Hi Team.&lt;/P&gt;&lt;P&gt;I have one SMS and two RA GW. The first RA GW configured that send into vpn tunnel only needed subnets other traffic send to local ISP.&amp;nbsp; The second GW configured that send all traffic into vpn tunnel and exclude some subnets to local ISP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now I have problem when user connect to the first GW, they received route that configured on the second GW. But on the 1st GW configure correct VPN Domain and user must receive route&amp;nbsp; to vpn tunnel for some subnets.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 14:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221481#M3447</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-07-21T14:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221489#M3448</link>
      <description>&lt;P&gt;By design, when you “add new site” you get information about all VPN gateways managed by the same SMS.&lt;BR /&gt;Version/JHF level along with a diagram of what you’re trying to achieve will help tremendously.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 15:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221489#M3448</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-21T15:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221492#M3449</link>
      <description>&lt;P&gt;Version: R81.10 Take 150.&lt;/P&gt;&lt;P&gt;I installed two different RA GW, disable MEP.&lt;/P&gt;&lt;P&gt;And I want when users connect to first RA GW only office subnets route to vpn tunnel and other traffic through local ISP.&lt;/P&gt;&lt;P&gt;And when user connect to second RA GW all traffic route to vpn.&lt;/P&gt;&lt;P&gt;Now when user connect to first RA VPN that all traffic route to vpn and ignore VPN Domains for this GW.&lt;/P&gt;&lt;P&gt;I configured different VPN Domains.&lt;/P&gt;&lt;P&gt;Subnets that need route on first and second RA GW overlaps, because second RA GW route all traffic to vpn.&lt;/P&gt;&lt;P&gt;Is it possible using one SMS have two different rule for RA VPN?&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 17:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221492#M3449</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-07-21T17:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221493#M3450</link>
      <description>&lt;P&gt;I think if you read below link ,it will clear certain things up. Specially section that talkes about IMPLICIT mep...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 17:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221493#M3450</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-21T17:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221494#M3451</link>
      <description>&lt;P&gt;I read this. MEP is disabled.&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 18:00:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221494#M3451</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-07-21T18:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221495#M3452</link>
      <description>&lt;P&gt;So please answer this question...how are enc domains configured? Is it overlapping or they have seperate subnets/groups? This info is IMPORTANT.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 18:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221495#M3452</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-21T18:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221496#M3453</link>
      <description>&lt;P&gt;VPN-SINet-Subnets has list of subnets&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;ED-remoteaccess has All-Internet-group&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 18:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221496#M3453</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-07-21T18:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221497#M3454</link>
      <description>&lt;P&gt;In such case, document says to follow ttm file to be manual, ie domains are NOT overlapping, which they are not in your case. I had done this for customers before and we followed exactly what it shows in the link I sent you, no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jul 2024 18:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221497#M3454</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-21T18:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221505#M3455</link>
      <description>&lt;P&gt;I am not sure that understood.&lt;/P&gt;&lt;P&gt;Now I have config ttm file:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;automatic_mep_topology - false&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;mep_mode - dns_based&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;enable_gw_resolving - true&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And nothing worked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 02:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221505#M3455</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-07-22T02:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221506#M3456</link>
      <description>&lt;P&gt;I will check in the morning, as I have this working in the lab. Make sure to follow al the steps from that document, it works 100%.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 03:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221506#M3456</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-22T03:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221556#M3457</link>
      <description>&lt;P&gt;There's an SK that covers this specific scenario:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk111995" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111995&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 12:55:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221556#M3457</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-22T12:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221558#M3458</link>
      <description>&lt;P&gt;Interesting...never recall having to follow this sk before.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 12:58:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/221558#M3458</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-22T12:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222487#M3459</link>
      <description>&lt;P&gt;Problem was decided when remove MEP in the file trac.defaults . Disable MEP from GW side did not work&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:52:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222487#M3459</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-08-01T14:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222488#M3460</link>
      <description>&lt;P&gt;Thats what document was indicating as well.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222488#M3460</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-01T14:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222490#M3461</link>
      <description>&lt;P&gt;In the document indicated on GW side (need edit file on GW), I removed on client side (edit client file).&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222490#M3461</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-08-01T14:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222491#M3462</link>
      <description>&lt;P&gt;Never had to do that myself...what are versions of the gw/client?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:58:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222491#M3462</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-01T14:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222492#M3463</link>
      <description>&lt;P&gt;GW - R81.10 Take 150, Client 88.30 and 86.50&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 15:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222492#M3463</guid>
      <dc:creator>Air</dc:creator>
      <dc:date>2024-08-01T15:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel and exclude subnets</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222493#M3464</link>
      <description>&lt;P&gt;Done it with those versions, NEVER have I had to modify anything on the client side.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 15:04:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-and-exclude-subnets/m-p/222493#M3464</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-01T15:04:47Z</dc:date>
    </item>
  </channel>
</rss>

