<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN with Two Public IP Address for Two Different Segment in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108507#M9261</link>
    <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We plane to configured Two Remote Access VPN&amp;nbsp; community.&lt;/P&gt;&lt;P&gt;Like we already have a LAN Segment (LAN_A) with IPS 1 Public IP address with remote access VPN configuration and which is currently working.&lt;/P&gt;&lt;P&gt;Now we added one more Segment (LAN_B) which we want to configured Remote Access VPN with New introduce ISP 2 Public IP address.&lt;/P&gt;&lt;P&gt;So Like Both community should work&amp;nbsp; such as LAN_A &amp;gt;&amp;gt; ISP1 &amp;amp; LAN_B &amp;gt;&amp;gt; ISP2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this Possible ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any alternative way to do that ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Currently we mention as Statically NATed IP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn.PNG" style="width: 766px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10293iF72828E650B4929E/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn.PNG" alt="vpn.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 10:56:48 GMT</pubDate>
    <dc:creator>Chinmaya_Naik</dc:creator>
    <dc:date>2021-01-22T10:56:48Z</dc:date>
    <item>
      <title>Remote Access VPN with Two Public IP Address for Two Different Segment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108507#M9261</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We plane to configured Two Remote Access VPN&amp;nbsp; community.&lt;/P&gt;&lt;P&gt;Like we already have a LAN Segment (LAN_A) with IPS 1 Public IP address with remote access VPN configuration and which is currently working.&lt;/P&gt;&lt;P&gt;Now we added one more Segment (LAN_B) which we want to configured Remote Access VPN with New introduce ISP 2 Public IP address.&lt;/P&gt;&lt;P&gt;So Like Both community should work&amp;nbsp; such as LAN_A &amp;gt;&amp;gt; ISP1 &amp;amp; LAN_B &amp;gt;&amp;gt; ISP2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this Possible ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any alternative way to do that ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Currently we mention as Statically NATed IP:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn.PNG" style="width: 766px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10293iF72828E650B4929E/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn.PNG" alt="vpn.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 10:56:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108507#M9261</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2021-01-22T10:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with Two Public IP Address for Two Different Segment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108517#M9262</link>
      <description>&lt;P&gt;There is not a native way to do that as far as i know, but maybe someone else may know a feature i do not. To do that i would use one of these options:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;If you have a load balancer in front of the CheckPoint firewall &amp;gt;&amp;gt;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131612&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_self"&gt;&lt;SPAN&gt;Remote access VPN link selection with DNS resolving&lt;/SPAN&gt;&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;If there is not a load balancer, i would force users from LAN_A to resolve always ISP1 ip address using a FQDN1 vpn1.domain.com and LAN_B to resolve ISP2 ip address with FQDN vpn2.domain.com &amp;gt;&amp;gt;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103440&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_self"&gt;How to force Remote Access VPN Client to resolve DNS name of VPN Site at every connection&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Consider that no matter which ISP the users connect to, the reply packets will always go trough the default route. A workwaround for this was provided by Thiago_Mourao here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/How-to-configure-VPN-Remote-Access-on-non-default-Internet-Link/m-p/81991" target="_self"&gt;How to configure VPN Remote Access on non-default Internet Link&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It is not very clear if LAN_A and LAN_B are office mode segments or lan networks behind the gateway, but if you need to use 2 differen IP segments for remote users, you will have to configure the first one on smatconsole and second one at ipassignment.conf file:&amp;nbsp;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422&amp;amp;partition=Advanced&amp;amp;product=SecureClient," target="_self"&gt;&lt;SPAN&gt;Office Mode IP and ipassignment.conf file&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The configuration made on the screenshot you posted is applied also to site-to-site tunnels, so i would use link selection for remote access only, all available options are described here:&amp;nbsp;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92383&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_self"&gt;Remote Access clients can connect to VPN Gateway only once&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also it is not supported to have a secon vpn community, or at least it was not the last time i asked.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 13:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108517#M9262</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2021-01-22T13:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with Two Public IP Address for Two Different Segment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108581#M9263</link>
      <description>&lt;P&gt;You can only have one Remote Access community per gateway.&lt;BR /&gt;This might possibly be a good use case for VSX.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 01:31:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/108581#M9263</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-23T01:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with Two Public IP Address for Two Different Segment</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/110254#M9264</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for the details.&lt;/P&gt;&lt;P&gt;have you tested on your LAB environment ?&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 06:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-Two-Public-IP-Address-for-Two-Different/m-p/110254#M9264</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2021-02-09T06:21:14Z</dc:date>
    </item>
  </channel>
</rss>

