<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I need to reconfigure our RAVPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205611#M4062</link>
    <description>&lt;P&gt;So is there any way to set it up where it won't cache (and we need two DNS entries (one for each gateway), or where it will go seamlessly between either at any point ?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 19:09:32 GMT</pubDate>
    <dc:creator>championc1</dc:creator>
    <dc:date>2024-02-09T19:09:32Z</dc:date>
    <item>
      <title>Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205496#M4056</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;We have a singular DNS name pointing at the public IP of our primary R81.20 Cluster.&amp;nbsp; If this primary clusters' public IP is unavailable, the VPN client re-directs itself to a secondary DR cluster.&lt;BR /&gt;&lt;BR /&gt;But if I understand it correctly, it seems like the secondary address is cached in the client meaning that, when the primary IP is reachable again, the client continues to connect to the secondary cluster gateway until such time as the VPN profile on the users' laptop is deleted and re-created.&lt;BR /&gt;&lt;BR /&gt;Ideally, I would like to have a setup where the endpoint becomes somewhat invisible to the user.&amp;nbsp; If the user connected to the secondary due to the unavailability of the primary, that it would revert back if the primary became availablke again, or if the secondary became unavailable.&lt;BR /&gt;&lt;BR /&gt;Could I implement an active - active setup, where it became pot luck as to which gateway the user connected to ?&amp;nbsp; &lt;SPAN&gt;&lt;SPAN class=""&gt;Would "First to Respond" MEP mode be the way to go&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 16:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205496#M4056</guid>
      <dc:creator>championc1</dc:creator>
      <dc:date>2024-02-08T16:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205500#M4057</link>
      <description>&lt;P&gt;Sounds like thats more site to site VPN mep, if this is for remote access vpn clients, you need to follow below&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 17:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205500#M4057</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-08T17:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205564#M4058</link>
      <description>&lt;P&gt;Yes, I found that previously, and that was why I referenced the question of "First to Respond"&lt;BR /&gt;&lt;BR /&gt;I'm looking for guidance on what is the best way to have RA configured in order that the Client profiles will never have to be deleted and re-created, and where either site can be connected to automatically without the need for a user to select between choosing the Primary or Secondary site&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 11:07:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205564#M4058</guid>
      <dc:creator>championc1</dc:creator>
      <dc:date>2024-02-09T11:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205574#M4059</link>
      <description>&lt;P&gt;It also depends on whether its implicit method or not, meaning whether both gateways have overlapping enc. domains. I will tell you, couple of customers I did this for, we used implicit primary-backup, worked like a charm. Reason was also because they did NOT want their users to see list of gateways they can connect to, which definitely made sense to me. So, if one was to ever fail, people would be able to connect to the other one.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 12:11:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205574#M4059</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-09T12:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205605#M4060</link>
      <description>&lt;P&gt;Does it sound correct that the Client caches the secondary ip accress in the event of a primary unavailability, and that when the primary returns, that connections continue to the secondary, and the only way that you can reconnect back to the primary is by recreating the profile pointing at the primary ip address&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This appears to be the way that our is functioning.&amp;nbsp; If this is so, what can I do to make it so that all always work&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 17:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205605#M4060</guid>
      <dc:creator>championc1</dc:creator>
      <dc:date>2024-02-09T17:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205606#M4061</link>
      <description>&lt;P&gt;Correct. Put it this way...I know this may sound like a stupid comparisino, but its sort of like how you need a browser on windows to open web pages, this is the same philisophy (if you will), client will "fetch" the information from the gateway side, so whatever is configured there, client would have that cashed.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 17:48:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205606#M4061</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-09T17:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205611#M4062</link>
      <description>&lt;P&gt;So is there any way to set it up where it won't cache (and we need two DNS entries (one for each gateway), or where it will go seamlessly between either at any point ?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 19:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205611#M4062</guid>
      <dc:creator>championc1</dc:creator>
      <dc:date>2024-02-09T19:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205612#M4063</link>
      <description>&lt;P&gt;You may want to confirm with TAC, but I believe those things can be manipulated in trac ttm file.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 19:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205612#M4063</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-09T19:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need to reconfigure our RAVPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205717#M4064</link>
      <description>&lt;P&gt;In the "first to respond" case the client always try to connect to the last known GW, as it will be probed first. You need to configure primary / backup option in MEP settings.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;See more details in the&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Manual-MEP.htm?tocpath=Configuring%20Client%20Features%7CMultiple%20Entry%20Point%20(MEP)%7C_____3" target="_self"&gt;&lt;SPAN class="MCBreadcrumbsDivider"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Multiple Entry Point (MEP)&lt;SPAN class="MCBreadcrumbsDivider"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="MCBreadcrumbsSelf"&gt;Manual MEP&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;admin guide section for RAS VPN&lt;/P&gt;</description>
      <pubDate>Mon, 12 Feb 2024 07:58:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Do-I-need-to-reconfigure-our-RAVPN/m-p/205717#M4064</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-02-12T07:58:02Z</dc:date>
    </item>
  </channel>
</rss>

