<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Remote Access VPN domain for different gateways in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149693#M6692</link>
    <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;I have the following issue to resolve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Two gateways for company users Remote access with same VPN RA domain configured - working ok.&lt;BR /&gt;We need to add third gateway for External Vendors with different VPN RA domain.&lt;/P&gt;&lt;P&gt;All three gateway are defined in the Remote Access community, MEP is turned off.&lt;/P&gt;&lt;P&gt;Everything works, except that external vendors gets the same routing table as defined for company users.&lt;/P&gt;&lt;P&gt;Am I doing something wrong? Is there some manual way to define required routes to be installed for the third gateway.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 30 May 2022 07:59:03 GMT</pubDate>
    <dc:creator>Dilian_Chernev</dc:creator>
    <dc:date>2022-05-30T07:59:03Z</dc:date>
    <item>
      <title>Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149693#M6692</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;I have the following issue to resolve &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Two gateways for company users Remote access with same VPN RA domain configured - working ok.&lt;BR /&gt;We need to add third gateway for External Vendors with different VPN RA domain.&lt;/P&gt;&lt;P&gt;All three gateway are defined in the Remote Access community, MEP is turned off.&lt;/P&gt;&lt;P&gt;Everything works, except that external vendors gets the same routing table as defined for company users.&lt;/P&gt;&lt;P&gt;Am I doing something wrong? Is there some manual way to define required routes to be installed for the third gateway.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 07:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149693#M6692</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2022-05-30T07:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149700#M6693</link>
      <description>&lt;P&gt;Easy - you can use either two RA communities or Access Roles to get a very granular access policy - see&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Configuring-Policy.htm?tocpath=Configuring%20Policy%20for%20Remote%20Access%20VPN%7C_____0#Configuring_Remote_Access_Policy" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Configuring-Policy.htm?tocpath=Configuring%20Policy%20for%20Remote%20Access%20VPN%7C_____0#Configuring_Remote_Access_Policy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 08:35:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149700#M6693</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-30T08:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149708#M6694</link>
      <description>&lt;P&gt;Don't think multiple Remote Access communities are supported.&amp;nbsp; It was possible to create multiple RA communities at one stage, but &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Multiple-Remote-Access-Communities-GW-Version/td-p/10807" target="_self"&gt;this was a bug.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Like you said - Identity based policies using Access Roles would be the way to go here.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 09:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149708#M6694</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-05-30T09:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149710#M6695</link>
      <description>&lt;P&gt;Yes, i would suggest to use Access Roles. Another possible configuration uses User Groups in access rules.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 10:48:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149710#M6695</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-30T10:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149714#M6696</link>
      <description>&lt;P&gt;Thank you for the response, but I don't have issues with rules, but with injected routes on client machines &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As usual it is more complicated than it sounds &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On the first two gw, VPN domain is - All internet without Zoom/Webex services. ( I saw this configuration here somewhere). So clients receive huge routing table that points to the gateway, except for Zoom/Webex.&lt;/P&gt;&lt;P&gt;On the third gw, we want clients to receive only routes to allowed destinations and use their internet services directly, not through the gw. But in fact, they get the same routing tab as members of first two gw.&lt;/P&gt;&lt;P&gt;All remote access vpn domains are defined properly for each gw.&lt;BR /&gt;So I was thinking if there is some OS level configuration file that could help for this.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 11:10:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149714#M6696</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2022-05-30T11:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149715#M6697</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Check this sk:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92676&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_self"&gt;&lt;SPAN&gt;Remote Access client download routes from all gateways in the Remote Access Community&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think it fits your scenario, and yes, the solution seems to be configured at OS level. HTH.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149715#M6697</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-05-30T12:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149717#M6698</link>
      <description>&lt;P&gt;I would not suggest such a topology for RA clients. With Access Roles, only parts of the internal networks can be made available to a subgroup of clients.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:35:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149717#M6698</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-30T12:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149718#M6699</link>
      <description>&lt;P&gt;Here, no MEP is used, so&amp;nbsp;&lt;SPAN&gt;sk92676 should not apply.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149718#M6699</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-30T12:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149719#M6700</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have mep disabled too, but line&amp;nbsp;&lt;STRONG&gt;client_policies&amp;nbsp;&lt;/STRONG&gt;still presents&amp;nbsp;&lt;STRONG&gt;mep&amp;amp;#&amp;nbsp;&lt;/STRONG&gt;part. Just tested the sk and my routing table decreased from 321 routes to 65. Did not verify that those 65 correspond exactly to the RA vpn domain of the gateway i am connecting too, but think it is worth a try.&lt;/P&gt;
&lt;P&gt;Regard&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 12:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149719#M6700</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-05-30T12:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Remote Access VPN domain for different gateways</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149786#M6701</link>
      <description>&lt;P&gt;This sk seems promising!&lt;/P&gt;&lt;P&gt;I will try it!&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 07:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Custom-Remote-Access-VPN-domain-for-different-gateways/m-p/149786#M6701</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2022-05-31T07:00:07Z</dc:date>
    </item>
  </channel>
</rss>

