<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MEP only for selected gateways in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212634#M3827</link>
    <description>&lt;P&gt;Yes,&lt;BR /&gt;I confirm this is it !&lt;/P&gt;&lt;P&gt;Again ... completely forgot about manual MEP .... ehh &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So in case anybody will have the same "problem" - choose Manual MEP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Andy.&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Apr 2024 19:06:52 GMT</pubDate>
    <dc:creator>marcyn</dc:creator>
    <dc:date>2024-04-29T19:06:52Z</dc:date>
    <item>
      <title>MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212623#M3821</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;Let's suppose we have one SMS which can manage 10 SGs.&lt;BR /&gt;We manage 6 of these SGs, and rest (4) are managed by 3rd party company (we see these gateways in SMS, but somebody else manages them, and they have their own LANs, DMZs, etc).&lt;/P&gt;&lt;P&gt;And now we decided that we want to add 2 more SGs that will act as VPN gateway for our remote users.&lt;/P&gt;&lt;P&gt;As we all know MEP is enabled by default, which we can of course change from "true" to "false" or "client_decide".&lt;/P&gt;&lt;P&gt;So if MEP is set as "true" ... what will remote user see after he will add new site in&amp;nbsp;Check Point Mobile/Endpoint Connect ?&lt;BR /&gt;Soon after first connection topology will be downloaded from this VPN gateway and on next connection user will see a new option - select box - where he will see EACH AND EVERY gateway that are in RemoteAccess VPN Community.&lt;BR /&gt;If there will be only these newly added VPN gateways - he will see only these two.&lt;/P&gt;&lt;P&gt;But what if administrator from this 3rd party organisation will enable IPSec VPN blade and add one or more of these 4 SGs to the RemoteAccess VPN Community ?&lt;BR /&gt;Our remote users will see our 2 VPN gateways ... and these gateways of 3rd party organisation in this select box ... and 3rd party organisation remote users will see theirs gatewa ... and our 2 VPN gateways...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two questions:&lt;BR /&gt;1) Do you know if there is some option to "filter" which gateways could be chosen by remote users for MEP (so that ours remote users should see only our 2 VPN gateway, and remote users from 3rd party organisation should see only theirs 4 gateways) ?&lt;BR /&gt;I was thinking about trac_client_1.ttm file ... but I don't see anything about that...&lt;BR /&gt;However I know that this file doesn't contain everything ... for example if you want to allow remote users to exclude localy connected networks from Hub Mode ... you need to add special entry to this file.&lt;BR /&gt;So perhabs there is something similar regarding MEP ?&lt;BR /&gt;Eh... if we could have more then one RemoteAccess VPN Community .... but we can't &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2) Even if Customer will select one particular gateway from this select box ... client's application connects to different gateway (each and every time it is the first one from the list) - even that I have option "client_decide" in "automatic_mep_topology".&lt;BR /&gt;How can I change that. It looks like as if "client_decide" for "mep_mode" is the same as "first_to_respond"...&lt;BR /&gt;Or maybe each Customer should change file C:\Program Files (x86)\CheckPoint\Endpoint Connect\trac.defaults regarding MEP .... it would be absurd.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Excerpt from $FWDIR/conf/trac_client_1.ttm:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(...)
                :mep_mode (
                        :gateway (
                                :map (
                                        :dns_based (dns_based)
                                        :first_to_respond (first_to_respond)
                                        :primary_backup (primary_backup)
                                        :load_sharing (load_sharing)
                                        :client_decide (client_decide)
                                )
                                :default (client_decide)
                        )
                )
(...)

(...)
                :automatic_mep_topology (
                        :gateway (
                                :map (
                                        :false (false)
                                        :true (true)
                                        :client_decide (client_decide)
                                )
                                :default (true)
                        )
                )
(...)&lt;/LI-CODE&gt;&lt;P&gt;As you can see these are default settings.&lt;/P&gt;&lt;P&gt;I can understand that with "automatic_mep_topology" selected as "true" client's application will not be able to select gateway - this choice will be done "automatically" based on some parameters.&lt;BR /&gt;But if this option will be changed to "client_decide" ... in my opinion gateway that will be chosen, should be this one selected from select box by the user ....&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What do you think ?&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:00:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212623#M3821</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-04-29T18:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212624#M3822</link>
      <description>&lt;P&gt;Thats exactly how it works with that option client_decide, they would be given a choice when connecting.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212624#M3822</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T18:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212625#M3823</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Yup ... they are ... but as I described I don't want them to see each and every gateway that is added to RemoteAccess VPN Community &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;And ... maybe they have this option ... but it doesn't matter which gateway they will choose ... application will connect to the first gateway on the list anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:18:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212625#M3823</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-04-29T18:18:38Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212626#M3824</link>
      <description>&lt;P&gt;Wait, maybe I misunderstood. in case you do NOT want users to see the gateways, just choose whichever is deemed as primary, then choose option automatic mep topology to true, as per below, depending if its implicit or manual MEP.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 19:10:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212626#M3824</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T19:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212627#M3825</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Ah yes ... I completely forgot about manual mode for MEP ...&lt;/P&gt;&lt;P&gt;I will try this one:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Under mep_mode, change default (client_decide) to default(first_to_respond).
Under ips_of_gws_in_mep, change default (client_decide) to default(&amp;lt;PrimaryIP&amp;amp;#SecondaryIP&amp;amp;#TertiaryIP&amp;amp;#&amp;gt;).
For example, default(192.168.20.250&amp;amp;#192.168.20.240&amp;amp;#).&lt;/LI-CODE&gt;&lt;P&gt;It looks like it could be the option that I'm looking for ... "ips_of_gws_in_mep" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will let you know if it will work&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212627#M3825</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-04-29T18:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212628#M3826</link>
      <description>&lt;P&gt;Yep, thats it!&lt;/P&gt;
&lt;P&gt;Sure, hope it works.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 18:28:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212628#M3826</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T18:28:44Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212634#M3827</link>
      <description>&lt;P&gt;Yes,&lt;BR /&gt;I confirm this is it !&lt;/P&gt;&lt;P&gt;Again ... completely forgot about manual MEP .... ehh &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So in case anybody will have the same "problem" - choose Manual MEP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Andy.&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 19:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212634#M3827</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-04-29T19:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: MEP only for selected gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212635#M3828</link>
      <description>&lt;P&gt;FYFOC = for you, free of charge &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 19:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MEP-only-for-selected-gateways/m-p/212635#M3828</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T19:11:13Z</dc:date>
    </item>
  </channel>
</rss>

