<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connecting to Internal Network VPN/SSL Client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146527#M6954</link>
    <description>&lt;P&gt;Hello Abrecht,&lt;BR /&gt;&lt;BR /&gt;Your help resolved my case.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cristian Rosa&lt;BR /&gt;&lt;BR /&gt;CCSA&lt;/P&gt;</description>
    <pubDate>Tue, 19 Apr 2022 19:30:48 GMT</pubDate>
    <dc:creator>Cristian_Rosa</dc:creator>
    <dc:date>2022-04-19T19:30:48Z</dc:date>
    <item>
      <title>Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146413#M6941</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hello guys,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;How to prevent the user on the LAN internal network from connecting to the SSL VPN/Client itself.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We come across this case, where the user should only be able to access an SSL VPN/Client when they are internal, not when they are internal.&lt;BR /&gt;&lt;BR /&gt;I wouldn't want users to access our own SSL/Client VPN from the internal network.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Congrats,&lt;BR /&gt;&lt;BR /&gt;Cristian Rosa&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 14:32:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146413#M6941</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-18T14:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146414#M6942</link>
      <description>&lt;P&gt;Im not real sure what you are trying to achieve here. You dont want user thats internal to be able to access VPN client??&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 15:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146414#M6942</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-18T15:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146418#M6943</link>
      <description>&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;240&lt;/SPAN&gt; / 5,000&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Yes&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;When the user is inside the internal network, he connects to the SSL VPN as if he were externally.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Should this happen?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Does Checkpoint accept this connection, even the user within the internal network?&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I wish it weren't possible.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 18 Apr 2022 17:27:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146418#M6943</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-18T17:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146419#M6944</link>
      <description>&lt;P&gt;You can restrict it, but there is no need to do this from internal.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 17:59:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146419#M6944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-18T17:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146420#M6945</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;And how would I do?&lt;BR /&gt;&lt;BR /&gt;C&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;an you help me ?&lt;BR /&gt;&lt;BR /&gt;Congrats,&lt;BR /&gt;&lt;BR /&gt;Cristian Rosa&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 18:14:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146420#M6945</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-18T18:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146421#M6946</link>
      <description>&lt;P&gt;Dont you have the ability to select the interface its accesible from?&lt;/P&gt;&lt;P&gt;i got that on several things if you open the gateway properties&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 18:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146421#M6946</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2022-04-18T18:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146422#M6947</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I don't know how to inform.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I searched but couldn't find where to configure it.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 18:23:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146422#M6947</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-18T18:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146423#M6948</link>
      <description>&lt;P&gt;Honestly, I never heard of a way to do this specifically from the firewall object itself or even global properties. There might be some way possible via gw file trac_client_1.ttm, but not 100% sure how. Maybe someone else will chime in and confirm for you. Personally, there would need to be some sort of mechanism that would recognize user being internal that would prevent them from even being able to connect, unless they come from external source.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 18:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146423#M6948</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-18T18:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146425#M6949</link>
      <description>&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Yes&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Exactly.&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I think this is the way&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I hadn't seen that happen yet.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 18 Apr 2022 19:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146425#M6949</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-18T19:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146426#M6950</link>
      <description>&lt;P&gt;Lets see if someone else may have an idea, Im also interested to see the suggestions/advice or if its even possible.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2022 19:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146426#M6950</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-18T19:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146459#M6951</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71215"&gt;@Cristian_Rosa&lt;/a&gt;&amp;nbsp;you can disable the implied rule for MOB access if you switch your gateway object configuration "Accessibility" to "According to the Firewall policy"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-04-19 075749.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16082i0D9DDB5BDB3E5E95/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-04-19 075749.png" alt="Screenshot 2022-04-19 075749.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;With these setting you have to define access rules for access to the MobileAccessPortal like this one&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-04-19 080211.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16083iFB9D6CFA1D540310/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-04-19 080211.png" alt="Screenshot 2022-04-19 080211.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 06:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146459#M6951</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-19T06:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146465#M6952</link>
      <description>&lt;P&gt;Yep - it is rather old and called &lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/html_frameset.htm" target="_blank" rel="noopener"&gt;Location Awareness&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;SmartDashboard - go to &lt;/SPAN&gt;&lt;STRONG&gt;Policy&lt;/STRONG&gt;&lt;SPAN&gt; menu - click on &lt;/SPAN&gt;&lt;STRONG&gt;Global Properties...&lt;/STRONG&gt;&lt;SPAN&gt; - expand &lt;/SPAN&gt;&lt;STRONG&gt;Remote Access&lt;/STRONG&gt;&lt;SPAN&gt; - click on &lt;/SPAN&gt;&lt;STRONG&gt;Endpoint Connect&lt;/STRONG&gt;&lt;SPAN&gt; - in the &lt;/SPAN&gt;&lt;STRONG&gt;Connectivity Settings&lt;/STRONG&gt;&lt;SPAN&gt; section, refer to &lt;/SPAN&gt;&lt;STRONG&gt;Network Location Awareness&lt;/STRONG&gt;&lt;SPAN&gt; field - select &lt;/SPAN&gt;&lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;SPAN&gt; - click on &lt;/SPAN&gt;&lt;STRONG&gt;Configure...&lt;/STRONG&gt;&lt;SPAN&gt; button - enjoy the options...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 08:46:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146465#M6952</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-04-19T08:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146475#M6953</link>
      <description>&lt;P&gt;Ah, yes, good point, totally forgot about that.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 12:55:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146475#M6953</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-19T12:55:25Z</dc:date>
    </item>
    <item>
      <title>Re: Connecting to Internal Network VPN/SSL Client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146527#M6954</link>
      <description>&lt;P&gt;Hello Abrecht,&lt;BR /&gt;&lt;BR /&gt;Your help resolved my case.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cristian Rosa&lt;BR /&gt;&lt;BR /&gt;CCSA&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 19:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Connecting-to-Internal-Network-VPN-SSL-Client/m-p/146527#M6954</guid>
      <dc:creator>Cristian_Rosa</dc:creator>
      <dc:date>2022-04-19T19:30:48Z</dc:date>
    </item>
  </channel>
</rss>

