<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN Question in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171833#M5484</link>
    <description>&lt;P&gt;I only can understand your question 1: Full tunnel is how it usually does work, i saw nothing in the sk that could confuse anyone!&lt;/P&gt;
&lt;P&gt;You can find split tunneling in &lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;sk167000: How to configure &lt;STRONG&gt;Split&lt;/STRONG&gt; &lt;STRONG&gt;Tunnel&lt;/STRONG&gt; for Office 365 and other SaaS Applications&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;and &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;R81.20 Remote Access VPN Administration Guide - Dynamic &lt;STRONG&gt;Split&lt;/STRONG&gt; &lt;STRONG&gt;Tunneling&lt;/STRONG&gt; for SaaS Using Updatable Objects&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For Q2 you may talk about IP and Site name resolved by DNS, but i never heard of a VPN between DC and DRC (???)...&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 06:50:34 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-02-17T06:50:34Z</dc:date>
    <item>
      <title>Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171829#M5483</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;BR /&gt;&lt;BR /&gt;Right now im on implementing RA VPN in customer environment, &lt;SPAN&gt;but found difficulties in configuration.. i tried some config following Admin Guide and SK but the issue still persist :&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;By default, is the VPN checkpoint configuration full tunnel or split tunnel? as i know is full tunnel, but after i check this SK&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000&lt;/A&gt;&amp;nbsp;I become confused&lt;/LI&gt;&lt;LI&gt;About Domain Site, initially only using IP for site access, but now it will change to domain. I've changed but still can't, do you have any ideas for solving it?&lt;/LI&gt;&lt;LI&gt;There is a question from customer, if the domain for VPN between DC and DRC is made the same (redundant), is it possible? I was looking for this information but could not find it.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou Checkmates, looking forward the answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 05:02:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171829#M5483</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-02-17T05:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171833#M5484</link>
      <description>&lt;P&gt;I only can understand your question 1: Full tunnel is how it usually does work, i saw nothing in the sk that could confuse anyone!&lt;/P&gt;
&lt;P&gt;You can find split tunneling in &lt;A href="https://support.checkpoint.com/results/sk/sk167000" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;sk167000: How to configure &lt;STRONG&gt;Split&lt;/STRONG&gt; &lt;STRONG&gt;Tunnel&lt;/STRONG&gt; for Office 365 and other SaaS Applications&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;and &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Dynamic-Split-Tunneling-for-SaaS.htm" target="_blank" rel="noopener noreferrer"&gt;&lt;SPAN&gt;R81.20 Remote Access VPN Administration Guide - Dynamic &lt;STRONG&gt;Split&lt;/STRONG&gt; &lt;STRONG&gt;Tunneling&lt;/STRONG&gt; for SaaS Using Updatable Objects&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For Q2 you may talk about IP and Site name resolved by DNS, but i never heard of a VPN between DC and DRC (???)...&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 06:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171833#M5484</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T06:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171836#M5485</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;So by default the configuration is Full Tunnel right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou,&amp;nbsp; i will check it for the second link is it only applicable for 81.20 only? my customer still on 81.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im sorry for not clear enough about my question, for Q2 i mean like below&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaa.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19652iDBF4A0C638B7F49B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="aaa.png" alt="aaa.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When i used IP Public Address for&amp;nbsp;&lt;STRONG&gt;"site",&amp;nbsp;&lt;/STRONG&gt;users can connect normally. but when i was trying to change &lt;STRONG&gt;"site"&amp;nbsp;&lt;/STRONG&gt;access using domain like &lt;EM&gt;vpn.company.co.uk&lt;/EM&gt; user cant connect. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 07:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171836#M5485</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-02-17T07:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171840#M5486</link>
      <description>&lt;P&gt;What does the used client DNS resolve &lt;EM&gt;vpn.company.co.uk&lt;/EM&gt; to ? The IP must be known to the DNS.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 08:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171840#M5486</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-17T08:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171914#M5487</link>
      <description>&lt;P&gt;Split tunnel (allowing direct access to Internet versus routing all traffic through the VPN headend) is the default.&lt;BR /&gt;You change this in Global Properties &amp;gt; Remote Access &amp;gt; Endpoint Connect &amp;gt; Route All Traffic to Gateway&lt;BR /&gt;There is also a setting on the client when the above setting is set to "Configured on Endpoint Client."&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For access by DNS name, that generally involves:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configuring Office Mode (requires appropriate licenses). This will assign the VPN client an IP address on the configured network and, more importantly, DNS servers for the client to use.&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If you are using SecuRemote (which does not have license requirements), refer to this for configuring SecuRemote DNS objects:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Quick-Primer-on-How-to-Configure-your-Gateway-for-SecuRemote/m-p/79081#M2717" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Quick-Primer-on-How-to-Configure-your-Gateway-for-SecuRemote/m-p/79081#M2717&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Depending on the precise requirements for accessing the Disaster site, you may want to configure Multiple Entry Point.&lt;BR /&gt;See: &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/MEP.htm&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 21:17:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/171914#M5487</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-17T21:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Question</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/188129#M5488</link>
      <description>&lt;P&gt;When using Office Mode (i.e with enterprise clients Endpoint Security VPN or Mobile VPN), how do you manage split DNS? If you provide your internal DNS via Office Mode (ex: DHCP), everything will be resolved via the internal DNS servers configured. How to force that public domains should be resolved via the LAN adapter (public ISP DNS servers) instead? From what I have observed and tested so far, the Checkpoint VPN adapter interface metric is lower (=0) compared to the LAN/WiFi interfaces on the computer, so has higher priority and takes precedence over the others, meaning everything will be resolved by the DNS specified via Office Mode.&lt;/P&gt;&lt;P&gt;I still have not found a way to manage split DNS properly (forcing public domains resolution not on the internal DNS servers) when using enterprise clients and Office mode... Any advice is welcome.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 15:39:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Question/m-p/188129#M5488</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2023-07-31T15:39:03Z</dc:date>
    </item>
  </channel>
</rss>

