<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Route VPN users through gateway for specific external sites only in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116569#M8814</link>
    <description>&lt;P&gt;Good day everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Hope everybody is keeping safe and healthy.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;So aside from access to our internal systems, our users also need access to external sites for research. These sites restrict access to our campus public IPs, so somehow i need to add specific routes on the VPN client side to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Can anyone point me to the right documentation? i've added external sites to the VPN domain(even though i'm not sure if this is wise). i've checked that routes indeed have been added to the client's routing table, and i've verified that traffic from VPN client -&amp;gt; external site is being allowed through...but it still doesn't work. Is there anything else i need to check/do ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 23:57:54 GMT</pubDate>
    <dc:creator>albertcuy</dc:creator>
    <dc:date>2021-04-21T23:57:54Z</dc:date>
    <item>
      <title>Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116569#M8814</link>
      <description>&lt;P&gt;Good day everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Hope everybody is keeping safe and healthy.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;So aside from access to our internal systems, our users also need access to external sites for research. These sites restrict access to our campus public IPs, so somehow i need to add specific routes on the VPN client side to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Can anyone point me to the right documentation? i've added external sites to the VPN domain(even though i'm not sure if this is wise). i've checked that routes indeed have been added to the client's routing table, and i've verified that traffic from VPN client -&amp;gt; external site is being allowed through...but it still doesn't work. Is there anything else i need to check/do ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 23:57:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116569#M8814</guid>
      <dc:creator>albertcuy</dc:creator>
      <dc:date>2021-04-21T23:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116575#M8815</link>
      <description>&lt;P&gt;I presume you need some NAT rules in place for this.&lt;BR /&gt;Have you configured that?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 05:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116575#M8815</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-22T05:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116578#M8816</link>
      <description>&lt;P&gt;Yes sir. i enabled the automatic NAT rules for the whole VPN subnet. But i don't see the NAT'ing in the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:02:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116578#M8816</guid>
      <dc:creator>albertcuy</dc:creator>
      <dc:date>2021-04-22T06:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116584#M8817</link>
      <description>&lt;P&gt;I presume you did it this way:&lt;/P&gt;
&lt;P&gt;Configure NAT for the Office Mode network:&lt;/P&gt;
&lt;OL type="A"&gt;
&lt;LI&gt;In SmartDashboard, open the Office Mode network properties.&lt;/LI&gt;
&lt;LI&gt;Go to "&lt;EM&gt;&lt;STRONG&gt;NAT&lt;/STRONG&gt;&lt;/EM&gt;" tab.&lt;/LI&gt;
&lt;LI&gt;Check the box "&lt;EM&gt;&lt;STRONG&gt;Add Automatic Address Translation rules&lt;/STRONG&gt;&lt;/EM&gt;".&lt;/LI&gt;
&lt;LI&gt;In "&lt;EM&gt;&lt;STRONG&gt;Translation method&lt;/STRONG&gt;&lt;/EM&gt;" field, select "&lt;EM&gt;&lt;STRONG&gt;Hide&lt;/STRONG&gt;&lt;/EM&gt;" and then select "&lt;EM&gt;&lt;STRONG&gt;Hide behind Gateway&lt;/STRONG&gt;&lt;/EM&gt;".&lt;/LI&gt;
&lt;LI&gt;Click on 'OK'.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116584#M8817</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-22T06:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116586#M8818</link>
      <description>&lt;P&gt;Yes sir, exactly like that &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:36:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116586#M8818</guid>
      <dc:creator>albertcuy</dc:creator>
      <dc:date>2021-04-22T06:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Route VPN users through gateway for specific external sites only</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116587#M8819</link>
      <description>&lt;P&gt;What version/JHF level?&lt;BR /&gt;Seems like it might be a bug since many customers use a similar configuration (albeit using "Route All Traffic").&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Route-VPN-users-through-gateway-for-specific-external-sites-only/m-p/116587#M8819</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-22T06:38:23Z</dc:date>
    </item>
  </channel>
</rss>

