<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RA clients receive unnecessary routes in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RA-clients-receive-unnecessary-routes/m-p/217809#M3673</link>
    <description>&lt;P&gt;Not sure the exclusions prevent the routes from being received by the client.&lt;BR /&gt;This should probably be confirmed with TAC.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2024 16:43:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-06-17T16:43:56Z</dc:date>
    <item>
      <title>RA clients receive unnecessary routes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RA-clients-receive-unnecessary-routes/m-p/217258#M3672</link>
      <description>&lt;P&gt;Hi mates!&lt;/P&gt;&lt;P&gt;We noticed that RA clients receive the routes from networks that are excluded from VPN community.&lt;/P&gt;&lt;P&gt;1. We followed sk167000 and&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; a. Set the value of the "Route all traffic to gateway" parameter to "No".&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; b. Created a network object (A) for excluded domain&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; c. We created another network object "Group with Exclusions" (B) and excluded the previous network group (A) from it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; d. Added a network group with exceptions (B) to the Remote Access Community and enabled Hub Mode.&lt;/P&gt;&lt;P&gt;2. While connecting to the VPN, we noticed that the client is receiving routing information from an excluded network group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that the clients will receive all the routes from all the participating gateways, but it feels a little unsecure knowing that any RA client will know about the networks that they are not supposed to.&lt;/P&gt;&lt;P&gt;Is there a way to prevent RA clients to&amp;nbsp;&lt;EM&gt;not&amp;nbsp;&lt;/EM&gt;receive routing from excluded networks?&lt;/P&gt;&lt;P&gt;We are on Maestro R81.10 Take 139.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 06:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RA-clients-receive-unnecessary-routes/m-p/217258#M3672</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-06-13T06:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: RA clients receive unnecessary routes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RA-clients-receive-unnecessary-routes/m-p/217809#M3673</link>
      <description>&lt;P&gt;Not sure the exclusions prevent the routes from being received by the client.&lt;BR /&gt;This should probably be confirmed with TAC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 16:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RA-clients-receive-unnecessary-routes/m-p/217809#M3673</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-17T16:43:56Z</dc:date>
    </item>
  </channel>
</rss>

