<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Intranet Connection in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197482#M4429</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To update, I was able to solve the problem.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I noticed, that the flow was "incomplete".&lt;/P&gt;
&lt;P&gt;It turns out that there was no Firewall rule that allows the connection of the IP pool of the users that connect through the RA VPN to the server that owns the domain.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I would still like to clarify a doubt.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have a web service that you publish to the Internet, when you log in through RA VPN, with the Internal DNS provided by the VPN, and you try to access that web service, the network card of the user's PC, to which DNS gives "more priority" at the moment of consuming the service? Is it the DNS assigned to me by the VPN, or is it the DNS of my Local ISP?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help and clarification.&lt;/P&gt;</description>
    <pubDate>Wed, 08 Nov 2023 17:25:38 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-11-08T17:25:38Z</dc:date>
    <item>
      <title>No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197371#M4421</link>
      <description>&lt;P&gt;Hello, Team.&lt;/P&gt;
&lt;P&gt;I have a problem with a VPN user connection, which is connected by Endpoint Security VPN agent.&lt;/P&gt;
&lt;P&gt;The user logs in, no problem, but once connected, when he tries to access an internal resource (INTRANET).&lt;BR /&gt;The access to the internal resource is a URL.&lt;/P&gt;
&lt;P&gt;I have a couple of doubts:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1- In the Firewall rule, should the DNS service be allowed, for this type of connection?&lt;/P&gt;
&lt;P&gt;2- In which part of the Remote Access VPN configuration, can I be sure that the company's internal DNS are being delivered to the VPN users' connections?&lt;/P&gt;
&lt;P&gt;Thanks for the clarification.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 00:16:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197371#M4421</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-08T00:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197379#M4422</link>
      <description>&lt;P&gt;Did you define an access rule for the RA users ?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 08:05:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197379#M4422</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-11-08T08:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197421#M4423</link>
      <description>&lt;P&gt;What are your office mode settings, DNS suffixes etc?&lt;/P&gt;
&lt;P&gt;Are you seeing logs indicating DNS traffic is being dropped?&lt;/P&gt;
&lt;P&gt;Are the remote access clients MacOS or Windows?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 12:19:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197421#M4423</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-08T12:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197428#M4424</link>
      <description>&lt;P&gt;Below is what you need, make sure its correct.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23103i504E68C5E83B5135/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197428#M4424</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T13:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197431#M4425</link>
      <description>&lt;P&gt;Indeed. Just don't expect Google to resolve your internal URLs. &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:22:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197431#M4425</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-08T13:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197432#M4426</link>
      <description>&lt;P&gt;Thats why this is a lab &lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 13:24:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197432#M4426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T13:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197448#M4427</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a question.&lt;/P&gt;
&lt;P&gt;If the resource to which you want to access, is a resource that is published both on the Internet, as well as a resource that can be consumed by Intranet, when you are already logged in to the VPN, and try to consume this resource, let's say the URL is &lt;A href="https://dev.example.com" target="_blank"&gt;https://dev.example.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;When you are connected to the VPN, and the user tries to open this resource, would it be using the Internal DNS of the VPN, or the External ones that you have from your local ISP connection?&lt;/P&gt;
&lt;P&gt;Which DNS takes the highest priority?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 15:11:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197448#M4427</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-08T15:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197449#M4428</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Chris can confirm for you, but Im pretty sure it would go based on the priority list from screenshot I sent...primary, first backup, second backup.&lt;/P&gt;
&lt;P&gt;You got my direct email, so we can do remote and I can show you in my R81.20 lab.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 15:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197449#M4428</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T15:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197482#M4429</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To update, I was able to solve the problem.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I noticed, that the flow was "incomplete".&lt;/P&gt;
&lt;P&gt;It turns out that there was no Firewall rule that allows the connection of the IP pool of the users that connect through the RA VPN to the server that owns the domain.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I would still like to clarify a doubt.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you have a web service that you publish to the Internet, when you log in through RA VPN, with the Internal DNS provided by the VPN, and you try to access that web service, the network card of the user's PC, to which DNS gives "more priority" at the moment of consuming the service? Is it the DNS assigned to me by the VPN, or is it the DNS of my Local ISP?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help and clarification.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197482#M4429</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-08T17:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197483#M4430</link>
      <description>&lt;P&gt;It all depends on the fact what DNS is able to resolve once connected, thats all.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 17:36:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197483#M4430</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T17:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197519#M4431</link>
      <description>&lt;P&gt;Generally, the default DNS of the client gets replaced by whatever the gateway assigns after the Remote Access client connects and gets an Office Mode address assigned.&lt;BR /&gt;However, there is nothing preventing the end user from changing their DNS configuration if they have admin rights to their local PC.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 22:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197519#M4431</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-08T22:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197523#M4432</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;makes an excellent point, as always. There is literally nothing stopping a person once they connect to RA to change DNS servers, as long as they have admin access to the local PC. Not quite certain about this, "MAYBE" that can be controlled by harmony endpoint product, but again, I could be mistaken on that part.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:00:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197523#M4432</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T23:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197524#M4433</link>
      <description>&lt;P&gt;We don't control those settings, but I assume the settings can be locked via GPO or similar.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197524#M4433</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-08T23:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: No Intranet Connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197526#M4434</link>
      <description>&lt;P&gt;Got it, makes sense.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:03:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/No-Intranet-Connection/m-p/197526#M4434</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-08T23:03:37Z</dc:date>
    </item>
  </channel>
</rss>

