<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing table when connected to SNX in Network Mode Only in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158701#M6217</link>
    <description>&lt;P&gt;The routes injected to the remote access clients should match the Remote Access Encryption Domain settings.&lt;BR /&gt;It therefore must be removed, not added.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2022 16:30:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-10-03T16:30:59Z</dc:date>
    <item>
      <title>Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158139#M6212</link>
      <description>&lt;P&gt;We are trying to switch to Unified Access Policy.&lt;BR /&gt;When connecting to SNX in Network Mode Only, third party users, lose their local network.&amp;nbsp;&lt;BR /&gt;A lot of routes are prescribed on the PC.&amp;nbsp;&lt;BR /&gt;There are no routing problems when working with Legacy Policy, but when switching to UAP, there is a route to two subnets with the gateway specified from the IP Pool of Issued Addresses.&lt;BR /&gt;Can you tell me why these routes are created? Maybe we missed something when configuring Unified Access Policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:47:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158139#M6212</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2022-09-27T09:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158196#M6213</link>
      <description>&lt;P&gt;Are the networks in question included in the encryption domain?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 16:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158196#M6213</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-27T16:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158267#M6214</link>
      <description>&lt;P&gt;No. Clients are connected via Mobile Access to SNX.&lt;BR /&gt;And once connected, they lose their local network.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 07:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158267#M6214</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2022-09-28T07:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158450#M6215</link>
      <description>&lt;P&gt;Are you saying no because:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The networks aren't in the encryption domain (you've checked and confirmed this)&lt;/LI&gt;
&lt;LI&gt;You &lt;EM&gt;&lt;STRONG&gt;believe&lt;/STRONG&gt;&lt;/EM&gt; the encryption domain doesn't apply because you're using MAB and SNX&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Whether it's one of the regular Remote Access clients or SNX in Network Mode, the routes received by the client will match what is configured in the Remote Access Encryption Domain.&lt;BR /&gt;This may not be the case in legacy mode, but in Unified Access Policy mode, this is definitely the case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 14:15:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158450#M6215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-29T14:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158655#M6216</link>
      <description>&lt;P&gt;That is, in order to ensure that users do not lose their local network, network must be added to the remote access encryption domain in the gateway settings?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 07:55:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158655#M6216</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2022-10-03T07:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158701#M6217</link>
      <description>&lt;P&gt;The routes injected to the remote access clients should match the Remote Access Encryption Domain settings.&lt;BR /&gt;It therefore must be removed, not added.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 16:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/158701#M6217</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-03T16:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/159524#M6218</link>
      <description>&lt;P&gt;In the encryption domain we have the internal subnets 192.168.0.0 and 172.16.0.0.&lt;BR /&gt;If we select "All IP Addresses behind Cluster Members based on Topology information" these subnets will also be in the encryption domain.&lt;BR /&gt;Do you mean use the encryption domain without any subnets?&lt;BR /&gt;Or should we add the subnets to the exception in "Set Specific VPN Domain for Gateway Communities", just like in sk167000?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 09:24:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/159524#M6218</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2022-10-14T09:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Routing table when connected to SNX in Network Mode Only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/159594#M6219</link>
      <description>&lt;P&gt;You need to modify the encryption domain so the subnets you don't want to inject to your remote clients are not included in the definition.&lt;BR /&gt;The approach mentioned&amp;nbsp;in sk167000 should work for this case, though you don't necessarily need to use "any" here.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 17:18:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Routing-table-when-connected-to-SNX-in-Network-Mode-Only/m-p/159594#M6219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T17:18:13Z</dc:date>
    </item>
  </channel>
</rss>

