<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access - IP Pool Configuration in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152364#M6502</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I assume you are using SNX or the Mobile Access vpn client on your remote machines in order to get an Office Mode IP address, it would be useful a capture what you see to understand better.&amp;nbsp; I will assume you are checking only the logs for decrypted packets, maybe there is a NAT causing this behavior. To start you can go to the logs and look for blade:"Mobile Access" search your login and take note of the office mode ip assigned, then look for that IP address and check what you see, if there is a NAT you should find it here.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 16:45:34 GMT</pubDate>
    <dc:creator>RS_Daniel</dc:creator>
    <dc:date>2022-07-05T16:45:34Z</dc:date>
    <item>
      <title>Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152350#M6497</link>
      <description>&lt;P&gt;Halo All,&lt;/P&gt;&lt;P&gt;I was enable Mobile Access Blade for SSL VPN and follow the wizard.&lt;/P&gt;&lt;P&gt;And this is the traffic : USER (public) —INTERNET— Mobile Access (R81.10) — Core — Internal Apps.&lt;/P&gt;&lt;P&gt;Mobile Access has 2 interface :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ETH1 : Public IP (facing to internet + portal access)&lt;/LI&gt;&lt;LI&gt;ETH2 : Local IP (point2point with Core)&lt;/LI&gt;&lt;LI&gt;+ IP Pool VPN (default segment IP)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And Mobile Access configuration like below :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Enable Office Mode + IP Pool" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17110i5818E0D94A61F2A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="exampleConfig.png" alt="Enable Office Mode + IP Pool" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Enable Office Mode + IP Pool&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is, why all Mobile Access user when access to internal apps detected using ETH2 IP (Local IP) not Pool VPN IP? When i check on Mobile Access Log, there are only Public IP information from user.&lt;/P&gt;&lt;P&gt;Based on above information, is my configuration wrong? any additional configuration needed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thankyou!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 14:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152350#M6497</guid>
      <dc:creator>tropicanaslim</dc:creator>
      <dc:date>2022-07-05T14:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152351#M6498</link>
      <description>&lt;P&gt;&lt;STRONG&gt;See&amp;nbsp;&lt;SPAN class="Book_Variablestp_full_book_title"&gt;Mobile Access R80.10 Administration Guide:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/131215.htm#o101280" target="BODY"&gt;&lt;STRONG&gt;&amp;nbsp;Office Mode&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 14:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152351#M6498</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-07-05T14:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152358#M6499</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i just compared my configuration with admin guide.&lt;/P&gt;&lt;P&gt;On &lt;EM&gt;$FWDIR/conf/ipassignment.conf&amp;nbsp;&lt;/EM&gt;i make sure on this config file there is no configuration related to Local IP and Pool VPN IP. So in my opinion will take over by &lt;EM&gt;Manual (using IP Pool),&amp;nbsp;&lt;/EM&gt;but i dont know why on Application detect the user using ETH2 Local IP, not Pool VPN IP. This one make me confused.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:47:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152358#M6499</guid>
      <dc:creator>tropicanaslim</dc:creator>
      <dc:date>2022-07-05T15:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152360#M6500</link>
      <description>&lt;P&gt;I believe ipassignment.conf would take precedence.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:56:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152360#M6500</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-05T15:56:13Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152362#M6501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9110"&gt;@Theo&lt;/a&gt;&amp;nbsp;yeah i believe so earlier, but after check the&amp;nbsp;&lt;EM&gt;$FWDIR/conf/ipassignment.conf&amp;nbsp;&lt;/EM&gt;there is no configuration related to IP that i used on the firewal..&lt;/P&gt;&lt;P&gt;This is the capture :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="default setting ipassignment" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17111i892586FB202C1AB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="ipassign.png" alt="default setting ipassignment" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;default setting ipassignment&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152362#M6501</guid>
      <dc:creator>tropicanaslim</dc:creator>
      <dc:date>2022-07-05T16:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152364#M6502</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I assume you are using SNX or the Mobile Access vpn client on your remote machines in order to get an Office Mode IP address, it would be useful a capture what you see to understand better.&amp;nbsp; I will assume you are checking only the logs for decrypted packets, maybe there is a NAT causing this behavior. To start you can go to the logs and look for blade:"Mobile Access" search your login and take note of the office mode ip assigned, then look for that IP address and check what you see, if there is a NAT you should find it here.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152364#M6502</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-07-05T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152394#M6503</link>
      <description>&lt;P&gt;Likely a NAT issue.&lt;/P&gt;
&lt;P&gt;I suggest creating a NO_NAT_for_Remote_Access rule in your NAT policy and configuring it as:&lt;/P&gt;
&lt;P&gt;CP_Default_Office_Mode_Pool to Internal_Networks, Original, Original.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 03:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152394#M6503</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-07-06T03:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152397#M6504</link>
      <description>&lt;P&gt;Agree, likely your hitting default/atuo NAT rules similar to:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17114i10BE4A7ECED3E92A/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT.png" alt="NAT.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 03:31:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152397#M6504</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-06T03:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152448#M6505</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply, currently i dont have access to the Gateway. i will it again on Thursday.&lt;/P&gt;&lt;P&gt;your suggestion is using manual nat or automatic nat? because i did some nat test before, by default VPN-IP-Pool is enable Hide NAT like below, but after i uncheck the NAT option, there is no differentiation. Is it similar with your suggestion using Manual NAT or Automatic NAT?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example - i did uncheck NAT option" style="width: 544px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17120i91F68A384DD04E05/image-size/large?v=v2&amp;amp;px=999" role="button" title="74016_pastedImage_3.png" alt="example - i did uncheck NAT option" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;example - i did uncheck NAT option&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 15:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152448#M6505</guid>
      <dc:creator>tropicanaslim</dc:creator>
      <dc:date>2022-07-06T15:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152451#M6506</link>
      <description>&lt;P&gt;Both, Automatic NAT and Manual NAT should be used simultaneously. But if the properties of your Office Mode Pool look like the screenshot above, they are misconfigured. Use this one for references:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Office-Mode_Pool-NAT.png" style="width: 511px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17121iCFA3C7A53F1EBBD2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Office-Mode_Pool-NAT.png" alt="Office-Mode_Pool-NAT.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Set the Pool NAT properties as shown above, but add the NonNAT_Rule I have suggested previously.&lt;/P&gt;
&lt;P&gt;If you are using Remote access with DNS forwarding to HQ and egress to the Internet resources, you want the pool to be NATed going outside. For access to internal resources, you do not- hence the Non_NAT Rule.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 15:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152451#M6506</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-07-06T15:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access - IP Pool Configuration</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152459#M6507</link>
      <description>&lt;P&gt;Right, thats what every default ipassignment.conf would look like, so it does not appear it was modified manually.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 18:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-IP-Pool-Configuration/m-p/152459#M6507</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-06T18:50:12Z</dc:date>
    </item>
  </channel>
</rss>

