<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic routine difference between ssl network extender and mobile client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/routine-difference-between-ssl-network-extender-and-mobile/m-p/151046#M6580</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;running&lt;/P&gt;&lt;P&gt;R80.30 Gaia 2.6.18 Jumbo Hotfix Accumulator Security Gateway and Standalone General&lt;BR /&gt;Availability (Take 226)&lt;/P&gt;&lt;P&gt;Client : Windows 10.&lt;/P&gt;&lt;P&gt;noted something weird. The public ip mentioned underneath is one of our own.&amp;nbsp; It's not in any encryption domain.&lt;/P&gt;&lt;P&gt;1. Connected using mobile vpn&lt;/P&gt;&lt;P&gt;A http connection to a specific public ip address works without any problem when using the mobile client.&amp;nbsp; The public ip is routed through the internet.&amp;nbsp; A 'netstat -rn' does not reveal any route forcing it to go through the vpn tunnel.&amp;nbsp; This is expected behaviour.&lt;/P&gt;&lt;P&gt;2. Connected using portal, and using ssl network extender&lt;/P&gt;&lt;P&gt;A http connection to a specific public ip address does not work.&amp;nbsp; A closer inspection reveals the packet is routed inside the vpn tunnel, and then ofcourse blocked on one of our firewalls due to "&lt;SPAN&gt;unauthorized ssl vpn traffic".&amp;nbsp; A 'netstat -rn' reveals a route forcing it to go trough the vpn tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can't explain the routing behaviour?&amp;nbsp; It's my expectation the routing table should come from the ras vpn domain.&amp;nbsp; And should be the same for both connecting methods?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 11:32:39 GMT</pubDate>
    <dc:creator>pnobels</dc:creator>
    <dc:date>2022-06-16T11:32:39Z</dc:date>
    <item>
      <title>routine difference between ssl network extender and mobile client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/routine-difference-between-ssl-network-extender-and-mobile/m-p/151046#M6580</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;running&lt;/P&gt;&lt;P&gt;R80.30 Gaia 2.6.18 Jumbo Hotfix Accumulator Security Gateway and Standalone General&lt;BR /&gt;Availability (Take 226)&lt;/P&gt;&lt;P&gt;Client : Windows 10.&lt;/P&gt;&lt;P&gt;noted something weird. The public ip mentioned underneath is one of our own.&amp;nbsp; It's not in any encryption domain.&lt;/P&gt;&lt;P&gt;1. Connected using mobile vpn&lt;/P&gt;&lt;P&gt;A http connection to a specific public ip address works without any problem when using the mobile client.&amp;nbsp; The public ip is routed through the internet.&amp;nbsp; A 'netstat -rn' does not reveal any route forcing it to go through the vpn tunnel.&amp;nbsp; This is expected behaviour.&lt;/P&gt;&lt;P&gt;2. Connected using portal, and using ssl network extender&lt;/P&gt;&lt;P&gt;A http connection to a specific public ip address does not work.&amp;nbsp; A closer inspection reveals the packet is routed inside the vpn tunnel, and then ofcourse blocked on one of our firewalls due to "&lt;SPAN&gt;unauthorized ssl vpn traffic".&amp;nbsp; A 'netstat -rn' reveals a route forcing it to go trough the vpn tunnel.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can't explain the routing behaviour?&amp;nbsp; It's my expectation the routing table should come from the ras vpn domain.&amp;nbsp; And should be the same for both connecting methods?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 11:32:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/routine-difference-between-ssl-network-extender-and-mobile/m-p/151046#M6580</guid>
      <dc:creator>pnobels</dc:creator>
      <dc:date>2022-06-16T11:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: routine difference between ssl network extender and mobile client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/routine-difference-between-ssl-network-extender-and-mobile/m-p/151047#M6581</link>
      <description>&lt;P&gt;if I were you, I would run route print on client's machine to see the difference.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 11:35:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/routine-difference-between-ssl-network-extender-and-mobile/m-p/151047#M6581</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-16T11:35:34Z</dc:date>
    </item>
  </channel>
</rss>

