<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split tunnel for User/Usergroup in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146096#M6968</link>
    <description>&lt;P&gt;Split tunneling is a global setting, unfortunately, so it applies to everyone.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2022 13:53:27 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-04-12T13:53:27Z</dc:date>
    <item>
      <title>Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146082#M6966</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a request from our customer to implement split tunnel solution for certain user/users. Currently they have full tunnel remote access VPN.&lt;/P&gt;&lt;P&gt;I've found sk167000 (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167000&lt;/A&gt;) tested it also in lab environment and it works great. But it's only applicable for a VPN community.&lt;/P&gt;&lt;P&gt;Is it possible to implement split tunneling somehow for a user group?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Zsolt&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 12:47:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146082#M6966</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2022-04-12T12:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146085#M6967</link>
      <description>&lt;P&gt;I believe below is what you are looking for:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16024iACE0897E2BE26378/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; Andy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 12:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146085#M6967</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-12T12:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146096#M6968</link>
      <description>&lt;P&gt;Split tunneling is a global setting, unfortunately, so it applies to everyone.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 13:53:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146096#M6968</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-12T13:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146162#M6969</link>
      <description>&lt;P&gt;I believe this option just defines which with authentication method can user authenticate on the VPN client.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 07:09:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146162#M6969</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2022-04-13T07:09:44Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146163#M6970</link>
      <description>&lt;P&gt;That's what I thought. Thanks, PhoneBoy!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 07:10:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146163#M6970</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2022-04-13T07:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146182#M6971</link>
      <description>&lt;P&gt;route all traffic to gateway (yes/no/decide on endpoint)&lt;/P&gt;&lt;P&gt;make the default in the trac.default file to route all traffic to gateway, but tell specific users to manually untick the checkbox in their client?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 09:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146182#M6971</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2022-04-13T09:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146195#M6972</link>
      <description>&lt;P&gt;Sounds good. May I ask for an SK or example from where I can learn and test it?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 12:22:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146195#M6972</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2022-04-13T12:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146253#M6973</link>
      <description>&lt;P&gt;in the global properties you set the "route all traffic to gateway" to "configured on endpoint client" for oth the secureclient mobile and endpoint connect options&lt;/P&gt;&lt;P&gt;on the gateway object you tick the box for "allow vpn clients to route traffic through this gateway" and you configure the remote access encryption domain for the split vpn users&lt;/P&gt;&lt;P&gt;if the end user connects once to the gateway, the setting to route all traffic to gateway will no longer be greyed out and the user can freely choose between full tunnel or split tunnel&lt;/P&gt;&lt;P&gt;you could create a new vpn package one for full tunnel users and one for split tunnel users and install accordingly, that way you don't have to teach them about the setting&lt;/P&gt;&lt;P&gt;download the tool from &lt;SPAN&gt;sk122574&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;i believe you need the setting "neo_route_all_traffic_through_gateway"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 06:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146253#M6973</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2022-04-14T06:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Split tunnel for User/Usergroup</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146280#M6974</link>
      <description>&lt;P&gt;Thanks Jan!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Meanwhile I've found sk114882. Based on that and your help it works for me in lab environment.&lt;/P&gt;&lt;P&gt;In addition to your settings I've modified the ttm files:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;In the test group file:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:neo_route_all_traffic_through_gateway (&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:gateway (endpoint_vpn_route_all_traffic_through_gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:default (client_decide)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the trac_client_1 file:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:neo_route_all_traffic_through_gateway (&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:gateway (endpoint_vpn_route_all_traffic_through_gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:valid (false)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;:default (true)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;)&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 13:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Split-tunnel-for-User-Usergroup/m-p/146280#M6974</guid>
      <dc:creator>zsszlama</dc:creator>
      <dc:date>2022-04-14T13:48:50Z</dc:date>
    </item>
  </channel>
</rss>

