<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access Link Selection - Staticaly Nated IP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121408#M8419</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Need suggestion on below&lt;/P&gt;&lt;P&gt;The customer has bought a range of IP Addresses from ISP, he wants to use one of the IP Addresses for checkpoint remote access VPN.&lt;/P&gt;&lt;P&gt;I believe we can use that IP Address in Statically Nat IP in link selection ( attached image).&lt;/P&gt;&lt;P&gt;Can anybody suggest what configuration is required from a policy perspective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karan&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 23:51:18 GMT</pubDate>
    <dc:creator>Karan0587</dc:creator>
    <dc:date>2021-06-16T23:51:18Z</dc:date>
    <item>
      <title>Remote Access Link Selection - Staticaly Nated IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121408#M8419</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Need suggestion on below&lt;/P&gt;&lt;P&gt;The customer has bought a range of IP Addresses from ISP, he wants to use one of the IP Addresses for checkpoint remote access VPN.&lt;/P&gt;&lt;P&gt;I believe we can use that IP Address in Statically Nat IP in link selection ( attached image).&lt;/P&gt;&lt;P&gt;Can anybody suggest what configuration is required from a policy perspective?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karan&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 23:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121408#M8419</guid>
      <dc:creator>Karan0587</dc:creator>
      <dc:date>2021-06-16T23:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Link Selection - Staticaly Nated IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121657#M8420</link>
      <description>&lt;P&gt;Beyond this configuration in Link Selection, you should not need to do anything unusual to accept the traffic.&lt;BR /&gt;It will be allowed by implied rules.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 00:48:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121657#M8420</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-21T00:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Link Selection - Staticaly Nated IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121659#M8421</link>
      <description>&lt;P&gt;As phoneboy said, config is fine, but as far as policy, just make sure that VPN traffic is allowed as usual, but other than that, you should be good to go.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 01:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121659#M8421</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-21T01:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Link Selection - Staticaly Nated IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121670#M8422</link>
      <description>&lt;P&gt;Thanks for the reply,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i thought so as well, but does not connect and goes through the clean up rule.&lt;/P&gt;&lt;P&gt;I have to create access policy rule to allo vpn for that IP&amp;nbsp; isn't ?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 01:31:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121670#M8422</guid>
      <dc:creator>Karan0587</dc:creator>
      <dc:date>2021-06-21T01:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access Link Selection - Staticaly Nated IP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121672#M8423</link>
      <description>&lt;P&gt;Not necessarily that IP, but object itself. So, you can make bi-directional rule for subnets involved (local and remote) and then under vpn column, just select that community, services you need and accept. If traffic fails on clean up rule, there is no any doubt that rule does not exist in the policy to allow it. Unless, the exception could be if you have layers, then it could be catching parent layered rule and then being dropped on explicit layer clean up rule, rather than implicit one, which would always be last rule in the rulebase.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 01:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-Link-Selection-Staticaly-Nated-IP/m-p/121672#M8423</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-21T01:34:57Z</dc:date>
    </item>
  </channel>
</rss>

