<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RAVPN Routing Issue in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/174643#M5356</link>
    <description>&lt;P&gt;Yes, you need routing, its not automatic for RA. Also, verify output of route print on the client from cmd.&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2023 18:09:54 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-03-13T18:09:54Z</dc:date>
    <item>
      <title>RAVPN Routing Issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/174642#M5355</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;so currently my cust on cluster mode and&amp;nbsp; enable RAVPN. but i facing an issue when remote user connect vpn they are cant reach to internal network.&lt;/P&gt;&lt;P&gt;for office mode if we use x.x.x.x/24 do we need to add this segment for routing table on each gateway? or routing for office mode will automatically enable?&lt;/P&gt;&lt;P&gt;since user could connect to vpn i think there is no issue for vpn configuration, or do i need to check something in remote access config?&lt;/P&gt;&lt;P&gt;then, does users when they connect to vpn automatically get full tunnel config by default? or need to config manually for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou..&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 18:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/174642#M5355</guid>
      <dc:creator>tropicanaslim</dc:creator>
      <dc:date>2023-03-13T18:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN Routing Issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/174643#M5356</link>
      <description>&lt;P&gt;Yes, you need routing, its not automatic for RA. Also, verify output of route print on the client from cmd.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2023 18:09:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/174643#M5356</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-13T18:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: RAVPN Routing Issue</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/176051#M5357</link>
      <description>&lt;P&gt;Here are the few things you need to check while configuring the RA VPN:&lt;/P&gt;
&lt;P&gt;Configuration:&lt;BR /&gt;++ IPSEC blade enabled.&lt;BR /&gt;++ GW object --&amp;gt; VPN client --&amp;gt; Office mode:&lt;BR /&gt;&amp;gt; Allow Office Mode to all users.&lt;BR /&gt;&amp;gt; Select the Manual Office Pool. If cluster then GW object --&amp;gt; Cluster Member --&amp;gt; Edit GW object --&amp;gt; VPN --&amp;gt; Check the Office Manual Office Mode.&lt;BR /&gt;++ GW object --&amp;gt; VPN client --&amp;gt; Remote Access --&amp;gt; Check Support Mode.&lt;BR /&gt;++ Ensure Gateway is added in the Remote Access community.&lt;BR /&gt;++ "All users*" should be allowed under the same Remote Access community.&lt;BR /&gt;++ Encryption domains should be defined then only you all access destination resources over RA VPN.&lt;/P&gt;
&lt;P&gt;GW object --&amp;gt; Expand Network Management --&amp;gt; VPN domain --&amp;gt; Set specific domain for community --&amp;gt; Remote access and set the Network group.&lt;BR /&gt;++ Access which allows traffic from the Office Mode pool towards the destination which you want to access.&lt;/P&gt;
&lt;P&gt;Basic T-shoot/Check:&lt;BR /&gt;++ Once the user has authenticated check "cmd&amp;gt; route print".&lt;BR /&gt;This output should show the destination IP route towards Office Mode IP, which destination IP traffic will go over the VPN towards the gateway.&lt;BR /&gt;++ Check Smart console logs for the same connection. It should be allowed on the access rule and under the same you can get an interface where this traffic is handled.&lt;BR /&gt;++ Usually you do not need any routing changes but ensure the gateway should be reached destination resources than on RAVPN client can access the resources.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:06:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/RAVPN-Routing-Issue/m-p/176051#M5357</guid>
      <dc:creator>girisht</dc:creator>
      <dc:date>2023-03-24T11:06:03Z</dc:date>
    </item>
  </channel>
</rss>

