<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Split Tunnel VPN for Office365 on Mobile devices in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/213947#M3803</link>
    <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Topo:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topo.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25627i2E9622A4A948AC38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="topo.jpg" alt="topo.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At the Mobile VPN, they have&amp;nbsp;a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web&amp;nbsp;related to Office365, which needs to automate route the traffic: client -&amp;gt; HQ -&amp;gt; O365.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Note: With endpoint devices VPN must route all traffic to HQ: endpoint -&amp;gt; HQ -&amp;gt; internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).&lt;BR /&gt;&lt;/EM&gt;&lt;BR /&gt;I had seen this sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank"&gt;How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com)&lt;/A&gt;, but seems like its&amp;nbsp;opposite with my case.&lt;BR /&gt;&lt;BR /&gt;Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?&lt;BR /&gt;&lt;BR /&gt;Please help me.&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; Best regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 12 May 2024 12:58:33 GMT</pubDate>
    <dc:creator>Phillip-83</dc:creator>
    <dc:date>2024-05-12T12:58:33Z</dc:date>
    <item>
      <title>Split Tunnel VPN for Office365 on Mobile devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/213947#M3803</link>
      <description>&lt;P&gt;Hi everyone,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Topo:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topo.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25627i2E9622A4A948AC38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="topo.jpg" alt="topo.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At the Mobile VPN, they have&amp;nbsp;a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web&amp;nbsp;related to Office365, which needs to automate route the traffic: client -&amp;gt; HQ -&amp;gt; O365.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;Note: With endpoint devices VPN must route all traffic to HQ: endpoint -&amp;gt; HQ -&amp;gt; internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).&lt;BR /&gt;&lt;/EM&gt;&lt;BR /&gt;I had seen this sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank"&gt;How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com)&lt;/A&gt;, but seems like its&amp;nbsp;opposite with my case.&lt;BR /&gt;&lt;BR /&gt;Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?&lt;BR /&gt;&lt;BR /&gt;Please help me.&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; Best regards.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 12:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/213947#M3803</guid>
      <dc:creator>Phillip-83</dc:creator>
      <dc:date>2024-05-12T12:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel VPN for Office365 on Mobile devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/213951#M3804</link>
      <description>&lt;P&gt;Just wondering, is this the case of customer wanting to assign different auth methods to different groups? If so, I dont believe thats possible as of yet. If I totally misunderstood, apologies.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 12 May 2024 13:31:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/213951#M3804</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-12T13:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel VPN for Office365 on Mobile devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214053#M3805</link>
      <description>&lt;P&gt;Because this is the usual use case: route everything except for Office 365.&lt;BR /&gt;To do what you're trying to do (route Office 365 traffic through the Remote Access VPN), see: &lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167000&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that you might want to investigate Harmony SASE for this use case.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 15:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214053#M3805</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-05-13T15:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel VPN for Office365 on Mobile devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214060#M3806</link>
      <description>&lt;P&gt;Ah, that sk, right.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 15:54:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214060#M3806</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-13T15:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Split Tunnel VPN for Office365 on Mobile devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214849#M3807</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with&amp;nbsp;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;STRONG&gt;o365_address_ranges&lt;/STRONG&gt;&lt;SPAN&gt;" and if needed other networks as member.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Doing so, all traffic to o365 will be routed via the security gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.&lt;/P&gt;&lt;P&gt;as therock mentioned, having multiple ... "VPN profiles"&amp;nbsp; you might likely run into limitations.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 15:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-Tunnel-VPN-for-Office365-on-Mobile-devices/m-p/214849#M3807</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2024-05-20T15:40:23Z</dc:date>
    </item>
  </channel>
</rss>

