<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Access in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130213#M7997</link>
    <description>&lt;P&gt;I can tell you from my own experience, best way to do this is create rule(s) to allow traffic from certain country (countries) and then create a rule below that to block traffic from that country.&lt;/P&gt;
&lt;P&gt;So, say for example you wish to let people in subnet 10.40.30.0/24 access anything in Russia. You would create a rule with that subnet in source, then updatable object country as Russia, put service(s) and allow, but then right below that rule, you would create another rule that says source any to Russia, block.&lt;/P&gt;
&lt;P&gt;Does that make sense?&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2021 17:21:08 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-09-24T17:21:08Z</dc:date>
    <item>
      <title>VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130206#M7996</link>
      <description>&lt;P&gt;Hello friends&lt;/P&gt;&lt;P&gt;I have a doubt in the execution of an activity.&lt;BR /&gt;I have an SSL VPN and client on my firewall gateway R80.10 Manager R80.30&lt;BR /&gt;I want to block Geo Policy and the countries that I release I want some to use the VPN tunnel as a Gateway for all traffic&lt;BR /&gt;and other countries use their internet provider to access the internet.&lt;/P&gt;&lt;P&gt;Is it possible to do this someone has this experience and can share how to do it?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 15:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130206#M7996</guid>
      <dc:creator>Paschoal</dc:creator>
      <dc:date>2021-09-24T15:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130213#M7997</link>
      <description>&lt;P&gt;I can tell you from my own experience, best way to do this is create rule(s) to allow traffic from certain country (countries) and then create a rule below that to block traffic from that country.&lt;/P&gt;
&lt;P&gt;So, say for example you wish to let people in subnet 10.40.30.0/24 access anything in Russia. You would create a rule with that subnet in source, then updatable object country as Russia, put service(s) and allow, but then right below that rule, you would create another rule that says source any to Russia, block.&lt;/P&gt;
&lt;P&gt;Does that make sense?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 17:21:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130213#M7997</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-24T17:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130216#M7998</link>
      <description>&lt;P&gt;In order to have granular Geo Protection rules, the gateways need to be on R80.20 or above.&lt;BR /&gt;Which is highly recommended anyway since R80.10 is soon to be End of Support.&lt;/P&gt;
&lt;P&gt;You can configure it so the client can choose whether to route all traffic through the gateway or not.&lt;BR /&gt;However, you can't force some users to route all traffic and allow others to split tunnel.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 17:32:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130216#M7998</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-24T17:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130381#M7999</link>
      <description>&lt;P&gt;Hey Good afternoon&lt;/P&gt;&lt;P&gt;Yes it makes sense, I would create a Policy Access Control denying the origin of Russia and China and allowing Japan and USA.&lt;/P&gt;&lt;P&gt;But how do I release Japan using VPN SSL as default for external access such as google and USA use your local internet provider for external access, eg google&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 17:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130381#M7999</guid>
      <dc:creator>Paschoal</dc:creator>
      <dc:date>2021-09-27T17:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130383#M8000</link>
      <description>&lt;P&gt;Hey Good afternoon&lt;/P&gt;&lt;P&gt;I understand I understand that on R80.10 I can't force via manager some SSL VPN traffic and client via split tunnel and others using your local provider for external access?&lt;/P&gt;&lt;P&gt;But I can do this on R80.20 or higher.&lt;/P&gt;&lt;P&gt;And it is recommended that the user determine this locally in their Endpoint Security Checkpoin?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 17:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130383#M8000</guid>
      <dc:creator>Paschoal</dc:creator>
      <dc:date>2021-09-27T17:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130384#M8001</link>
      <description>&lt;P&gt;The options available&amp;nbsp;are basically: yes, no, and “client decide” where the client can choose whether to route all traffic through the VPN or not.&lt;BR /&gt;These options&amp;nbsp;can only be configured globally, not based on location or user group.&lt;BR /&gt;Newer versions than R80.10 are the same in this regard.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 18:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130384#M8001</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-27T18:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130395#M8002</link>
      <description>&lt;P&gt;Well, as I said, if you need to allow certain countries/services, you just make a rule to reflect that. Message me offline, we can do remote session and Im happy to show you.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 20:00:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Access/m-p/130395#M8002</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-27T20:00:19Z</dc:date>
    </item>
  </channel>
</rss>

