<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217199#M3739</link>
    <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 21:43:51 GMT</pubDate>
    <dc:creator>LifeisGood</dc:creator>
    <dc:date>2024-06-11T21:43:51Z</dc:date>
    <item>
      <title>VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217134#M3736</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a CP VPN connected to CP FW. There is a DMZ&amp;nbsp; (10.10.6.0/24 with 10.10.6.10 as the DMZ interface IP)&amp;nbsp;on the FW. My VPN client got a route from the VPN gateway to route everything to the VPN gateway's external interface (84.84.84.11). See attached topology for details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My VPN client can reach the DMZ interface IP on the FW (10.10.6.10). However, the client cannot reach any IPs (e.g. 10.10.6.38) in the DMZ subnet. If I add a host route on the VPN appliance (10.10.6.38/32 --&amp;gt; 10.10.6.10), then the VPN client can reach the host. Could someone help me understand why I have to add host route and how to avoid add 200+ host route for the DMZ hosts?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 15:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217134#M3736</guid>
      <dc:creator>LifeisGood</dc:creator>
      <dc:date>2024-06-11T15:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217169#M3737</link>
      <description>&lt;P&gt;Did you configure the Remote Access Encryption Domain to include the relevant DMZ networks?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 18:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217169#M3737</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-11T18:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217190#M3738</link>
      <description>&lt;P&gt;Is the VPN gateway 1 hop behind the firewall gateway? &amp;nbsp;Or is it parallel, with the VPN gateway's external interface sharing the same subnet as the firewall gateway? &amp;nbsp;Your network addressing makes it look parallel. &amp;nbsp;Your diagram also suggests the VPN gateway's internal interface has to pass traffic back through the firewall gateway on another interface (which is fine).&lt;/P&gt;
&lt;P&gt;In addition to the message from PhoneBoy (check his suggestion first), this also sounds like you are missing a return route on the firewall gateway for the office mode subnet (172.10.0/22). &amp;nbsp;I suspect your firewall gateway, or perhaps the VPN gateway, is performing NAT and you aren't expecting it. &amp;nbsp;The firewall gateway will see source IP packets of 172.10.0.0/22, so they need to be returned to the VPN gateway. &amp;nbsp;You can see this with fw monitor. &amp;nbsp;You can run this command on both gateways, which will give you a hint:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;fw monitor -F 172.20.1.2,0,0,0,0 -F 0,0,172.20.1.2,0,0&lt;/LI-CODE&gt;
&lt;P&gt;You can also check your logs and you will see if NAT is being applied.&lt;/P&gt;
&lt;P&gt;Similarly, make sure your interior network (10.10.6.0/24) has either a default route, or some type of route, to also send packets for 172.20.0.0/22 back to the firewall gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217190#M3738</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-06-11T21:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217199#M3739</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:43:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217199#M3739</guid>
      <dc:creator>LifeisGood</dc:creator>
      <dc:date>2024-06-11T21:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client cannot not reach host in a subnet, but can reach the subnet's Layer 3 interface IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217200#M3740</link>
      <description>&lt;P&gt;Per CP Support, FW and VPN appliances share interfaces, and all the addresses in those shared subnets on the FW side are considered in the same layer 2 network. That's why the class C route I put in place does not do anything and more specific host routes are working fine. The workaround is to break class C into specific /25 routes. This work around worked. Thank you all for your input.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-cannot-not-reach-host-in-a-subnet-but-can-reach-the/m-p/217200#M3740</guid>
      <dc:creator>LifeisGood</dc:creator>
      <dc:date>2024-06-11T21:49:10Z</dc:date>
    </item>
  </channel>
</rss>

