<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SDL with location awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128015#M8125</link>
    <description>&lt;P&gt;I am working on a specific requirement with Endpoint security VPN E84.40 clients. I read the admin guide in order to enable SDL and location awareness (Global properties&amp;gt;Endpoint connect). It contains a group with our internal IP addresses.&lt;/P&gt;&lt;P&gt;SDL is enabled on the client. Now when these users connect over an external network the SDL pops up which is good. But when the user comes into office the client pops up to connect on VPN again, as I understand client need to recognize that host is in a internal network and give a bypass on VPN client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a network with many locations linked by MPLS links and this problem happens just in locations connected on my Datacenter by MPLS, when I connect directly on my LAN on my DataCenter it no happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I raised a ticket with CP TAC and receive the answer that is necessary to be connected directly on the same network than my gateway, but it is not clear for me, because my locations is connected by MPLS but have access to firewall directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe there is a configuration missing in some point.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 21:18:52 GMT</pubDate>
    <dc:creator>rlamerico</dc:creator>
    <dc:date>2021-08-25T21:18:52Z</dc:date>
    <item>
      <title>SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128015#M8125</link>
      <description>&lt;P&gt;I am working on a specific requirement with Endpoint security VPN E84.40 clients. I read the admin guide in order to enable SDL and location awareness (Global properties&amp;gt;Endpoint connect). It contains a group with our internal IP addresses.&lt;/P&gt;&lt;P&gt;SDL is enabled on the client. Now when these users connect over an external network the SDL pops up which is good. But when the user comes into office the client pops up to connect on VPN again, as I understand client need to recognize that host is in a internal network and give a bypass on VPN client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a network with many locations linked by MPLS links and this problem happens just in locations connected on my Datacenter by MPLS, when I connect directly on my LAN on my DataCenter it no happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I raised a ticket with CP TAC and receive the answer that is necessary to be connected directly on the same network than my gateway, but it is not clear for me, because my locations is connected by MPLS but have access to firewall directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe there is a configuration missing in some point.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 21:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128015#M8125</guid>
      <dc:creator>rlamerico</dc:creator>
      <dc:date>2021-08-25T21:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128016#M8126</link>
      <description>&lt;P&gt;What settings are you using?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 21:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128016#M8126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-25T21:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128286#M8127</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;BR /&gt;&lt;BR /&gt;I have enabled the SDL on my client and configure "network location awareness" with my network range 10.0.0.0/8.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot_223.png" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13563iDC65A0F5E1229AB1/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_223.png" alt="Screenshot_223.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 17:44:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128286#M8127</guid>
      <dc:creator>rlamerico</dc:creator>
      <dc:date>2021-08-28T17:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128292#M8128</link>
      <description>&lt;P&gt;In the remote sites, it is connecting to the gateway via the internal interface or via the external interface?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 00:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128292#M8128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-29T00:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128364#M8129</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;BR /&gt;In remote sites, we have an MPLS connecting with my DataCenter, in this case we are connecting with the internal interface, but I don´t have a specific configuration for that, on my client, I just configure my external IP when creating a profile.&lt;/P&gt;&lt;P&gt;The only configuration that I have to inform what is my internal LAN is on "location awareness".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 14:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128364#M8129</guid>
      <dc:creator>rlamerico</dc:creator>
      <dc:date>2021-08-30T14:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128374#M8130</link>
      <description>&lt;P&gt;Have you confirmed traffic to the gateway's external IP is in fact traversing the MPLS?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 15:16:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128374#M8130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-30T15:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: SDL with location awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128401#M8131</link>
      <description>&lt;P&gt;Yes, in this case, the client can´t reach the gateway´s external IP and it is correct because he is on my LAN, in my mind the client when connected on the first time on VPN need to receive the topology and the information about my internal range and based on this information don´t request to connect when receive one ip from my internal range.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 02:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SDL-with-location-awareness/m-p/128401#M8131</guid>
      <dc:creator>rlamerico</dc:creator>
      <dc:date>2021-08-31T02:38:01Z</dc:date>
    </item>
  </channel>
</rss>

