<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Connect client behaviour changes in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107820#M9334</link>
    <description>&lt;P&gt;many thanks - can i also please query the MEP settings in dbedit&lt;/P&gt;&lt;P&gt;i currently have MEP disabled&amp;nbsp; - does this completely turn off MEP?&lt;/P&gt;&lt;P&gt;what is the effect to the vpn clients - should they now only connect to the gateway configured on the client 'site' ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="heavysoul_0-1610627362568.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10229i4AC303327C0FA093/image-size/medium?v=v2&amp;amp;px=400" role="button" title="heavysoul_0-1610627362568.png" alt="heavysoul_0-1610627362568.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 12:32:03 GMT</pubDate>
    <dc:creator>heavysoul</dc:creator>
    <dc:date>2021-01-14T12:32:03Z</dc:date>
    <item>
      <title>Endpoint Connect client behaviour changes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107755#M9332</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am experiencing strange vpn client (E82.40) behaviour recently, following the addition of a new interface in my topology.&lt;/P&gt;&lt;P&gt;I have 2 x 5600 (R80.20) gateway clusters - primary and backup site&lt;/P&gt;&lt;P&gt;I have single vpn domain across both sites&lt;/P&gt;&lt;P&gt;Endpoint Connect VPN clients (on W10)&amp;nbsp; have been connecting to primary site fine, all good&lt;/P&gt;&lt;P&gt;Following above change, clients:-&lt;/P&gt;&lt;P&gt;1) started connecting to the backup site at random&lt;/P&gt;&lt;P&gt;2) proxy settings on the client machines overwritten&lt;/P&gt;&lt;P&gt;3) certificate warning when connecting to backup site&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have disabled MEP via dbedit, but still connections to backup site continue&lt;/P&gt;&lt;P&gt;I have checked the MEP settings in each of the 4 gateway TTM files - all are configured as follows: -&lt;/P&gt;&lt;P&gt;A)&lt;/P&gt;&lt;P&gt;:automatic_mep_topology (&lt;BR /&gt;&amp;nbsp; &amp;nbsp;:gateway (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :map (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:false (false)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:true (true)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :default (true)&lt;/P&gt;&lt;P&gt;B)&lt;/P&gt;&lt;P&gt;:mep_mode (&lt;BR /&gt;&amp;nbsp; &amp;nbsp;:gateway (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :map (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:dns_based (dns_based)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:first_to_respond (first_to_respond)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:primary_backup (primary_backup)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:load_sharing (load_sharing)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :default (client_decide)&lt;BR /&gt;)&lt;BR /&gt;C)&lt;BR /&gt;:ips_of_gws_in_mep (&lt;BR /&gt;&amp;nbsp; &amp;nbsp;:gateway (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :default (client_decide)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the proxy settings for each TTM file and see my primary site gateway is configured: -&lt;/P&gt;&lt;P&gt;:do_proxy_replacement (&lt;BR /&gt;&amp;nbsp; &amp;nbsp;:gateway (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;:default (false)&lt;/P&gt;&lt;P&gt;However my backup site gateway is configured: -&lt;/P&gt;&lt;P&gt;:do_proxy_replacement (&lt;BR /&gt;&amp;nbsp; &amp;nbsp;:gateway (&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; :default (client_decide)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q- From the MEP config above am I correct in assuming the client is deciding upon which gateway to connect to?&lt;/P&gt;&lt;P&gt;Q - From the proxy config above am I correct to assume once clients connect to the backup site gateway, proxy settings are being overwritten/changed?&lt;/P&gt;&lt;P&gt;Q - Can someone confirm is there further config I require to create a primary/backup VPN solution where clients will connect only to the primary site as long as it is available, with the backup site available to make connections should primary fail?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 19:00:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107755#M9332</guid>
      <dc:creator>heavysoul</dc:creator>
      <dc:date>2021-01-13T19:00:03Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect client behaviour changes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107758#M9333</link>
      <description>&lt;P&gt;Client decide means exactly what it says: the client decides.&lt;BR /&gt;Yes, when you connect to the backup gateway with a different configuration, that configuration will apply.&lt;BR /&gt;Not sure you can “force” a configuration where the client can connect to the backup only when the primary is not available.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 20:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107758#M9333</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-13T20:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect client behaviour changes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107820#M9334</link>
      <description>&lt;P&gt;many thanks - can i also please query the MEP settings in dbedit&lt;/P&gt;&lt;P&gt;i currently have MEP disabled&amp;nbsp; - does this completely turn off MEP?&lt;/P&gt;&lt;P&gt;what is the effect to the vpn clients - should they now only connect to the gateway configured on the client 'site' ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="heavysoul_0-1610627362568.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10229i4AC303327C0FA093/image-size/medium?v=v2&amp;amp;px=400" role="button" title="heavysoul_0-1610627362568.png" alt="heavysoul_0-1610627362568.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 12:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107820#M9334</guid>
      <dc:creator>heavysoul</dc:creator>
      <dc:date>2021-01-14T12:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Connect client behaviour changes</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107881#M9335</link>
      <description>&lt;P&gt;Offhand, I don't know how to query that in dbedit, but assume it is (assuming it's a gateway parameter).&lt;BR /&gt;I believe it disables MEP, yes, and next time your clients connect, they should only connect to the primary site.&amp;nbsp;&lt;BR /&gt;If the secondary site is still configured for Remote Access, they may be able to manually add that as a site and connect.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2021 01:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Connect-client-behaviour-changes/m-p/107881#M9335</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-15T01:08:00Z</dc:date>
    </item>
  </channel>
</rss>

