<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN client from inside network in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146591#M6917</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My client's demand is to attempt to connect via endpoint vpn client from a WiFi network that is behind CP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have exempted Office Mode addresses from the external interface, however I am still not able to establish the connection..the vpn client gets stuck at 47%&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_client_vpn_connection_new.png" style="width: 415px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16096i890E935A9ABC1BF5/image-dimensions/415x267?v=v2" width="415" height="267" role="button" title="checkpoint_client_vpn_connection_new.png" alt="checkpoint_client_vpn_connection_new.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I get from the logs is the following:&lt;/P&gt;&lt;P&gt;16:57:49.995884 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.258470 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.522939 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.831110 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:51.050687 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;/P&gt;&lt;P&gt;Any guidance regarding this one ?&lt;/P&gt;&lt;P&gt;Let me specify that the external interface of Checkpoint is in the RFC1918 range and that the IPSEC Link selection mechanism is statically NATted where the red one is what is depicted as X.X.X.X in tcpdump.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="link-selection.PNG" style="width: 522px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16098i5C9929B03745EC89/image-dimensions/522x231?v=v2" width="522" height="231" role="button" title="link-selection.PNG" alt="link-selection.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2022 12:50:15 GMT</pubDate>
    <dc:creator>Nikolaos_Liakop</dc:creator>
    <dc:date>2022-04-20T12:50:15Z</dc:date>
    <item>
      <title>VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146591#M6917</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;My client's demand is to attempt to connect via endpoint vpn client from a WiFi network that is behind CP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have exempted Office Mode addresses from the external interface, however I am still not able to establish the connection..the vpn client gets stuck at 47%&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="checkpoint_client_vpn_connection_new.png" style="width: 415px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16096i890E935A9ABC1BF5/image-dimensions/415x267?v=v2" width="415" height="267" role="button" title="checkpoint_client_vpn_connection_new.png" alt="checkpoint_client_vpn_connection_new.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What I get from the logs is the following:&lt;/P&gt;&lt;P&gt;16:57:49.995884 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.258470 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.522939 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:50.831110 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;BR /&gt;16:57:51.050687 IP 192.168.244.20.10415 &amp;gt; X.X.X.X.ipsec-nat-t: NONESP-encap: isakmp: phase 2/others ? oakley-quick[E]&lt;/P&gt;&lt;P&gt;Any guidance regarding this one ?&lt;/P&gt;&lt;P&gt;Let me specify that the external interface of Checkpoint is in the RFC1918 range and that the IPSEC Link selection mechanism is statically NATted where the red one is what is depicted as X.X.X.X in tcpdump.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="link-selection.PNG" style="width: 522px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16098i5C9929B03745EC89/image-dimensions/522x231?v=v2" width="522" height="231" role="button" title="link-selection.PNG" alt="link-selection.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 12:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146591#M6917</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2022-04-20T12:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146595#M6918</link>
      <description>&lt;P&gt;The shown GW cluster properties for IP selection is used with S2S VPN, not RA VPN. As the client already is located behind the RA VPN GW, why is there any need to connect to the internal network using VPN ? If needed very hard, you could enable the internal IF for RA VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 13:29:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146595#M6918</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-20T13:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146596#M6919</link>
      <description>&lt;P&gt;Because WiFi is giving only internet access and there is a need for some clients to get access to the internal network and this can be accomplished only through the vpn client.&lt;/P&gt;&lt;P&gt;How can I enable internal interface access ?&lt;/P&gt;&lt;P&gt;Also the IP Link selection mechanism depicted in the screenshot is used with endpoint vpn clients as well. I have attempted to change the link selection mechanism to that of the external interface of CP which is the LAN link of the load balancer and is a RFC1918 interface and checked that the vpn client took as an ip address the private one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 13:38:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/146596#M6919</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2022-04-20T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/147083#M6920</link>
      <description>&lt;P&gt;Any update on this ?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 14:00:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/147083#M6920</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2022-04-26T14:00:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/187970#M6921</link>
      <description>&lt;P&gt;hello dear,&lt;/P&gt;
&lt;P&gt;did you solve the issue? are you able to connect to internal interface?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 14:52:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/187970#M6921</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-07-28T14:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/188122#M6922</link>
      <description>&lt;P&gt;Couldn't you setup a separate CORP SSID that is on a separate VLAN that has routes to internal resources?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 14:43:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/188122#M6922</guid>
      <dc:creator>JasonUllyot</dc:creator>
      <dc:date>2023-07-31T14:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/190029#M6923</link>
      <description>&lt;P&gt;We have exactly the same issue; guest wifi (internet only) users behind the same firewall that occasionally need to connect to corporate resources using a VPN to this same firewall.&amp;nbsp; Wish I could tell you that we solve this problem.&amp;nbsp; I would be interested if you find a solution.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 19:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/190029#M6923</guid>
      <dc:creator>Mike_Schepers</dc:creator>
      <dc:date>2023-08-21T19:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client from inside network</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/208843#M6924</link>
      <description>&lt;P&gt;Did someone solve this? I have a same kind of situation.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 06:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-client-from-inside-network/m-p/208843#M6924</guid>
      <dc:creator>Jere</dc:creator>
      <dc:date>2024-03-15T06:25:55Z</dc:date>
    </item>
  </channel>
</rss>

