<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understand Mobile access routing/split-tunelling and native applications in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Understand-Mobile-access-routing-split-tunelling-and-native/m-p/122811#M8352</link>
    <description>&lt;P&gt;If this is about Mobile Access Portal only, then Google is not an internal Web Application, so the comparison is wrong. Did you consult the&amp;nbsp;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Mobile Access R81 Administration Guide already ? If you use other CP RA VPN possibilities beside MAB (Capsule, Mobile, Endpoint Security VPN...) you can route all traffic through the main site to participate from GW TP / TE / TX like when situated in the internal company network.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2021 11:40:56 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-07-02T11:40:56Z</dc:date>
    <item>
      <title>Understand Mobile access routing/split-tunelling and native applications</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Understand-Mobile-access-routing-split-tunelling-and-native/m-p/122810#M8351</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling to understand how checkpoint Mobile Access handles routing and split-tunnel on remote clients.&lt;/P&gt;&lt;P&gt;I have Mobile Access with office mode. Doing some test I get this following logic. I will use an example tu explain the concept.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's assume this scenario:&lt;/P&gt;&lt;P&gt;I have 2 Remote users Mario and Luigi.&lt;/P&gt;&lt;P&gt;We have 2 native applications: Server A and Server B.&lt;/P&gt;&lt;P&gt;Mario has a rule that allows to reach Server A.&lt;/P&gt;&lt;P&gt;Luigi has a rule that allows to reach Server B.&lt;/P&gt;&lt;P&gt;If we give a look at Mario's (or Luigi is the same) routing table once connected to VPN, he has both routes to Server A and B pointing to VPN tunnel even if his not authorized to go to Server B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So default behavior is that everything is declared as Native Application will be pushed as a route to Remote Clients. It's correct?&lt;/P&gt;&lt;P&gt;I could accept this logic but I'm facing a funny issue. On a customer I found a similar scenario as described before, but just assume that this time Server B is a public server...let's say google.com.&lt;/P&gt;&lt;P&gt;The result is that Mario can go to Server A, but not to google.com even if could use it's own internet connection (split-tunnel).&lt;/P&gt;&lt;P&gt;Luigi instead can go to google.com but using the VPN tunnel through corporate network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's all correct or I'm missing some workaround or configuration to allow Mario to route traffic to goolge.com with out sending it to the VPN tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Gianluigi&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 11:13:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Understand-Mobile-access-routing-split-tunelling-and-native/m-p/122810#M8351</guid>
      <dc:creator>gcarella</dc:creator>
      <dc:date>2021-07-02T11:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Understand Mobile access routing/split-tunelling and native applications</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Understand-Mobile-access-routing-split-tunelling-and-native/m-p/122811#M8352</link>
      <description>&lt;P&gt;If this is about Mobile Access Portal only, then Google is not an internal Web Application, so the comparison is wrong. Did you consult the&amp;nbsp;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Mobile Access R81 Administration Guide already ? If you use other CP RA VPN possibilities beside MAB (Capsule, Mobile, Endpoint Security VPN...) you can route all traffic through the main site to participate from GW TP / TE / TX like when situated in the internal company network.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 11:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Understand-Mobile-access-routing-split-tunelling-and-native/m-p/122811#M8352</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-07-02T11:40:56Z</dc:date>
    </item>
  </channel>
</rss>

