<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Remote Access Communities (GW Version?) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179004#M5145</link>
    <description>&lt;P&gt;Unfortunately, a "site" refers to a management domain, not a gateway.&lt;BR /&gt;Which means both gateways will show up on your clients when you add one of them.&lt;/P&gt;
&lt;P&gt;MEP may not actually be needed here, upon further reflection.&lt;BR /&gt;Both gateways need to have the same encryption domain, obviously.&lt;BR /&gt;Do they have different Office Mode pools assigned?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2023 03:06:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-25T03:06:18Z</dc:date>
    <item>
      <title>Two Gateways Serving the Same Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178621#M5137</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've got 2 GWs at 2 different geographic locations.&amp;nbsp; We want to enable remote access on both of them.&amp;nbsp; The one at HQ is already up and running for a few years.&lt;/P&gt;
&lt;P&gt;The new one at our branch site is being set up now.&amp;nbsp; When I try to add the 2nd GW as part of the same RAC, it causes the production one to fail.&amp;nbsp; By "fail", I mean the user can successfully connect, but there would be no traffic through the tunnel.&amp;nbsp; &amp;nbsp;It would then keep asking the user to log in to the VPN again (eventhough it's still connected), this time it shows the 2nd GW name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I try to create a second RAC, I can't and you say it's not supported.&lt;/P&gt;
&lt;P&gt;How do I go about setting up the 2nd site as a VPN entry point?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;R80.40 3800 (HQ)&lt;/P&gt;
&lt;P&gt;R80.20 Quantum1800 (Branch)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 18:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178621#M5137</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-26T18:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178659#M5138</link>
      <description>&lt;P&gt;Make sure Secondary Connect is properly enabled.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Secondary-Connect.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Secondary-Connect.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 21:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178659#M5138</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-20T21:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178688#M5139</link>
      <description>&lt;P&gt;Thanks, but actually we don't need to allow the dynamic connection to 2 sites.&amp;nbsp; We just need to allow the user to connect to either site.&lt;/P&gt;&lt;P&gt;If I disable secondary connect without configuring the new site yet, would the existing site have any issues?&lt;/P&gt;&lt;P&gt;i.e. As it's a production environment, I want to do testing/configuring one step at a time, so if something goes wrong I know what I should rollback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to check the current status of secondary connect (enabled or disabled).&lt;/P&gt;&lt;P&gt;e.g. is there a &lt;STRONG&gt;get secondary_connect status&lt;/STRONG&gt; command? Or just check the&amp;nbsp;&lt;EM&gt;trac_client_1.ttm &lt;/EM&gt;file?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently to get the primary site back up and running, I have removed the secondary site from the RAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm thinking if I disable secondary connect first on all GWs, check that it's all working.&lt;/P&gt;&lt;P&gt;Add the secondary site back to the RAC, check that it's all working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would be the safest, with least downtime if it goes awry!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 08:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178688#M5139</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-21T08:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178711#M5140</link>
      <description>&lt;P&gt;Secondary Connect isn’t relevant if that’s your goal.&lt;BR /&gt;What you probably want is Multiple Entry Point (MEP).&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/MEP.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 11:47:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178711#M5140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T11:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178739#M5141</link>
      <description>&lt;P&gt;Is it necessary to use MEP?&lt;/P&gt;&lt;P&gt;Can we keep it simple and not use MEP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 14:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178739#M5141</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-21T14:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178751#M5142</link>
      <description>&lt;P&gt;The only way you can have multiple gateways managed by the same manager serve the same encryption domain is with MEP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 16:14:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178751#M5142</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T16:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178784#M5143</link>
      <description>&lt;P&gt;This is defined in trac_client_1.ttm and is the most appropriate place to check this.&lt;BR /&gt;Your approach for testing this seems appropriate.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 20:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178784#M5143</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-21T20:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178911#M5144</link>
      <description>&lt;P&gt;For MEP.&amp;nbsp; The description says the three methods/options are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First to respond&lt;/LI&gt;&lt;LI&gt;Primary/Backup&lt;/LI&gt;&lt;LI&gt;Random Selection&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to use the other site as a backup site, but it's on a different LAN (connected by an MPLS Intranet), to a different internet connection provided by a different ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The most appropriate method looks to me to be the Primary/Backup option.&amp;nbsp; However, having the set up as above, we would like users to manually select the other site, should the primary site go down.&amp;nbsp; &amp;nbsp;The above system would need DDNS or something?&lt;/P&gt;&lt;P&gt;Or the internal probing will push the user to the GW at the other site automatically, i.e:&lt;/P&gt;&lt;P&gt;Even if the user only has siteA.acme.com configured as a site on their machine, it will push them to siteB.acme.com automatically if SiteA is down?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would rather do it manually (i.e. create 2 sites for the users).&amp;nbsp; If we do do it manually, should we disable MEP?&lt;/P&gt;&lt;P&gt;Currently, we seem to be experiencing the symptoms described in this SK:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk78180" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk78180&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 10:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/178911#M5144</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-24T10:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179004#M5145</link>
      <description>&lt;P&gt;Unfortunately, a "site" refers to a management domain, not a gateway.&lt;BR /&gt;Which means both gateways will show up on your clients when you add one of them.&lt;/P&gt;
&lt;P&gt;MEP may not actually be needed here, upon further reflection.&lt;BR /&gt;Both gateways need to have the same encryption domain, obviously.&lt;BR /&gt;Do they have different Office Mode pools assigned?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 03:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179004#M5145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-25T03:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179241#M5146</link>
      <description>&lt;P&gt;Sorry, I did reply to this on Tuesday, but seems I didn't hit submit to send the message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, both GWs have separate Office Mode pools.&lt;/P&gt;&lt;P&gt;The primary one has Office Mode pool IPs from the HQ LAN&lt;/P&gt;&lt;P&gt;The new one has Office Mode pool IPs from the branch LAN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need users who connect to the Branch GW via VPN to be able to access resources on the whole intranet including at HQ&lt;/P&gt;&lt;P&gt;We need users who connect to the HQ GW via VPN to be able to access resources on the whole intranet including at the Branch.&lt;/P&gt;&lt;P&gt;The intranet is connected via an MPLS network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 14:30:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179241#M5146</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-04-26T14:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179259#M5147</link>
      <description>&lt;P&gt;As this discussion is clearly unrelated to the original thread this appeared in, I created a new thread and changed the subject.&lt;/P&gt;
&lt;P&gt;Regardless, what can you see on the gateway side when the user connects?&lt;BR /&gt;Are there any log entries related to the user when the connect?&lt;BR /&gt;Have you done any tcpdumps or similar to see if the traffic from the relevant users makes it in/out of the gateway?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 18:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179259#M5147</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-26T18:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Two Gateways Serving the Same Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179265#M5148</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We use that configuration with many customers. General steps: disable secondary connect, and disable mep. For second step you can check&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk78180" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk78180&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;With that configuration we are able to connect to each gateway independently. No Active/Backup, no conflicts with encryption domains, they are separeted remote access gateways.&lt;/P&gt;
&lt;P&gt;To verify trac_client file you can use this command:&amp;nbsp;&lt;SPAN&gt;vpn check_ttm &amp;lt;trac_client_1.ttm location&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 19:59:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179265#M5148</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-04-26T19:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Two Gateways Serving the Same Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179287#M5149</link>
      <description>&lt;P&gt;Good point. All that is also listed below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/html_frameset.htm?topic=documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_RemoteAccessVPN_AdminGuide/164758&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 01:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179287#M5149</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-27T01:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: Two Gateways Serving the Same Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179306#M5150</link>
      <description>&lt;P&gt;Interesting Discussion here,&amp;nbsp; a definitely MUST have features in Check Point future RFE inside SmartConsole&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 08:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/179306#M5150</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2023-04-27T08:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/180033#M5151</link>
      <description>&lt;P&gt;Sorry for the delayed reply.&amp;nbsp;&amp;nbsp;As a new thread was created, I didn't get the email notification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...So since the last message, I have disabled MEP and Secondary connect.&lt;/P&gt;&lt;P&gt;The original GW VPN is working fine now, even though I add the new GW to the same RAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I connect to the new GW VPN, if I don't add allow rules to the policy then I can see the packets drop in the logs.&lt;/P&gt;&lt;P&gt;However, when I add allow rules to the policy, the drop logs disappear and are replaced with:&lt;/P&gt;&lt;P&gt;tunnel_test (udp/18234)&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Decrypted in community RemoteAccess&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Implied Rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, no traffic passes, all ping/trace tests fail (rules added to allow ICMP).&lt;/P&gt;&lt;P&gt;I'm at a loss now and have no idea where to look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 07:56:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/180033#M5151</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-05-05T07:56:05Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/180102#M5152</link>
      <description>&lt;P&gt;Did you do a tcpdump on the other gateway to see if traffic actually gets there?&lt;BR /&gt;In any case, a TAC case is probably warranted here:&amp;nbsp;&lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 May 2023 22:24:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/180102#M5152</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-05T22:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Two Gateways Serving the Same Encryption Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181051#M5153</link>
      <description>&lt;P&gt;Thanks, I disabled Secondary Connect and MEP still no luck.&lt;/P&gt;&lt;P&gt;I ran the VPN check on all three trac_client_1.ttm files in below locations:&lt;/P&gt;&lt;P&gt;/pfrm2.0/config1/fw1/conf/trac_client_1.ttm&lt;BR /&gt;/pfrm2.0/config2/fw1/conf/trac_client_1.ttm&lt;BR /&gt;/pfrm2.0/opt/fw1/conf/trac_client_1.ttm&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all report back OK:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Summary for the file: trac_client_1.ttm&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;result: the file passed the check without any problems&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 07:22:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181051#M5153</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-05-16T07:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181057#M5154</link>
      <description>&lt;P&gt;I'm certain the traffic is reaching the GW because when a packet is blocked it shows up in the tracker.&amp;nbsp; However, once I add the rule to allow the packet&amp;nbsp; then it would change to:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;tunnel_test (udp/18234)&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Decrypted in community RemoteAccess&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Implied Rule&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, if I try to access an FTP server on the LAN and the rule does not exist, it will show:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - TO&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -rule&lt;/P&gt;&lt;P&gt;VPN client&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- FTP Server&amp;nbsp; &amp;nbsp; &amp;nbsp;- 21&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-cleanup rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;once I create a rule to allow the packet, then I will see:&lt;/P&gt;&lt;P&gt;From&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - TO&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - description&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -rule&lt;/P&gt;&lt;P&gt;VPN client&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- GW public IP&amp;nbsp; - tunnel_test (udp/18234)&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- Decrypted in community RemoteAccess&amp;nbsp; &amp;nbsp; &amp;nbsp; -cleanup rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already raised a ticket with TAC over a week a go, but no response.&amp;nbsp; I've got in contact with Checkpoint Account manager, but waiting for a response to that as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the mean time, from the tracker log result above, any idea why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 07:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181057#M5154</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-05-16T07:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181161#M5155</link>
      <description>&lt;P&gt;If it's hitting the cleanup rule, it means there's no matching rule in your rulebase to accept the traffic.&lt;BR /&gt;The rules would have to be written in terms of the unencrypted traffic (i.e. what the gateway sees after removing the IPsec headers, etc), possibly matching the RemoteAccess VPN community.&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2023 21:55:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181161#M5155</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-16T21:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Remote Access Communities (GW Version?)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181204#M5156</link>
      <description>&lt;P&gt;Sorry, I realized my table was incorrect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, yup I agree with that.&amp;nbsp; When I saw the traffic hit the cleanup rule, I immediately added the rule to allow it.&lt;/P&gt;&lt;P&gt;Once I allowed it, then it no longer hit the cleanup rule, but instead started showing the below hitting the Implied Rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BEFORE:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;From&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - TO&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -rule&lt;/P&gt;&lt;P&gt;VPN client&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- FTP Server&amp;nbsp; &amp;nbsp; &amp;nbsp;- 21&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-cleanup rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AFTER:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;From&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- TO&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - description&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -rule&lt;/P&gt;&lt;P&gt;VPN client&amp;nbsp; - GW public IP&amp;nbsp; - tunnel_test (udp/18234)&amp;nbsp; &amp;nbsp;- Decrypted in community RemoteAccess&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;STRONG&gt;-Implied Rule&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 08:13:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-Gateways-Serving-the-Same-Encryption-Domain/m-p/181204#M5156</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2023-05-17T08:13:35Z</dc:date>
    </item>
  </channel>
</rss>

