<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MGMT IP address not accessible via RA VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194679#M4505</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Anyone knows why a security gateway would exclude its management IP address out of the RA VPN client's routing table?&lt;/P&gt;&lt;P&gt;Case in point, the RA VPN community encryption domain includes the whole 10.0.0.0/8 subnet, yet the 10.0.0.X IP address, which is the management IP address of the security gateway where the RA VPN is terminated, is not included in the connected RA VPN client's routing table. The RA VPN client is&amp;nbsp; Check Point Mobile and uses IPsec to tunnel traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 15:02:52 GMT</pubDate>
    <dc:creator>AlexandruD</dc:creator>
    <dc:date>2023-10-10T15:02:52Z</dc:date>
    <item>
      <title>MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194679#M4505</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Anyone knows why a security gateway would exclude its management IP address out of the RA VPN client's routing table?&lt;/P&gt;&lt;P&gt;Case in point, the RA VPN community encryption domain includes the whole 10.0.0.0/8 subnet, yet the 10.0.0.X IP address, which is the management IP address of the security gateway where the RA VPN is terminated, is not included in the connected RA VPN client's routing table. The RA VPN client is&amp;nbsp; Check Point Mobile and uses IPsec to tunnel traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 15:02:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194679#M4505</guid>
      <dc:creator>AlexandruD</dc:creator>
      <dc:date>2023-10-10T15:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194699#M4506</link>
      <description>&lt;P&gt;I just checked in one of customers' environments and works fine, no issues. Can you see what is output of route print from user's machine?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 17:28:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194699#M4506</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T17:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194706#M4507</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Here is a snippet of a connected RA VPN client's provisioned routes. You can see that the routes exclude the specific 10.0.0.252 IP address (which is the MGMT address of the security gateway) from the rest of the routes within the 10.0.0.0/8 prefix.&amp;nbsp;I cannot find any specific configuration for this behavior via SmartConsole, perhaps there might be some parameter I could ajust directly in the DB.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-10 215138.png" style="width: 690px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22734i15FCFA8A2FA8BF2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-10 215138.png" alt="Screenshot 2023-10-10 215138.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Alexandru&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194706#M4507</guid>
      <dc:creator>AlexandruD</dc:creator>
      <dc:date>2023-10-10T19:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194711#M4508</link>
      <description>&lt;P&gt;I dont really see anything specific, below is just referred to dns when people log in via RA.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22735i5ADF75C0579F3A76/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:12:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194711#M4508</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T19:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194728#M4509</link>
      <description>&lt;P&gt;Location Awareness enabled, perhaps?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 21:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/194728#M4509</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-10T21:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/195564#M4510</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I finally got this working, it took a while for CP support to provide a fix, although a bit complicated for such a simple need:&lt;/P&gt;&lt;P&gt;- automatic MEP topology must be disabled oin the gateway, based on sk78180 (it already was disabled in my case)&lt;/P&gt;&lt;P&gt;- disable MEP topology retrieval in the VPN client's configuration, sk92676 (different than the default setting)&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-18 220607.png" style="width: 677px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22860i2C2CEB90FE44468B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-18 220607.png" alt="Screenshot 2023-10-18 220607.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Alexandru&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 19:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/195564#M4510</guid>
      <dc:creator>AlexandruD</dc:creator>
      <dc:date>2023-10-18T19:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: MGMT IP address not accessible via RA VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/195565#M4511</link>
      <description>&lt;P&gt;Thanks for the update! &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 19:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MGMT-IP-address-not-accessible-via-RA-VPN/m-p/195565#M4511</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-18T19:32:03Z</dc:date>
    </item>
  </channel>
</rss>

