<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98495#M9814</link>
    <description>&lt;P&gt;I'm using Checkpoint 5100&lt;/P&gt;&lt;P&gt;Firewall (IP 192.168.1.254) is connected to Azure via Route based with IP 10.x.x.x/16 with settings below;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings.PNG" style="width: 347px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8313i921D78A641BAFC07/image-dimensions/347x338?v=v2" width="347" height="338" role="button" title="vpn settings.PNG" alt="vpn settings.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings 1.PNG" style="width: 422px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8314i196C72289F2F8BCD/image-dimensions/422x296?v=v2" width="422" height="296" role="button" title="vpn settings 1.PNG" alt="vpn settings 1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings 2.PNG" style="width: 439px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8315i4200EC4CA8BB8D91/image-dimensions/439x269?v=v2" width="439" height="269" role="button" title="vpn settings 2.PNG" alt="vpn settings 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 Sites using def. Lan IP 192.168.1.0/24 and 192.168.2.0. Both sites are inter-connected via IPVPN/MPLS connection.&lt;/P&gt;&lt;P&gt;I create a network group called "MyLocalNetwork" which includes the following network (192.168.1.0/24, 192.168.2.0/24)&lt;/P&gt;&lt;P&gt;Source: MyLocalNetwork, AzureGW | Destination: MyLocalNetwork, AzureGW | VPN: AzureVPN | Services: Any | Action: Accept | Track: Lag&lt;/P&gt;&lt;P&gt;2 Sites can now access the Azure app via gateway of 1.0 and 2.0 going to Firewall (IP 192.168.1.254). All users of 2 Sites can access the apps via 10.x.x.x/16 just like local connection.&lt;/P&gt;&lt;P&gt;next&lt;/P&gt;&lt;P&gt;I configure the RemoteAccess Community by adding Gateway device to Participating gateway.&lt;/P&gt;&lt;P&gt;I created users and groups that i will add to Participant Users Groups at the VPN RemoteAccess Community.&lt;/P&gt;&lt;P&gt;I'm using Office Mode and use the Manual IP Pool which is the CP_default_Office_Mode_Address_Pool (172.16.10.0/24).&lt;/P&gt;&lt;P&gt;I add the&amp;nbsp;CP_default_Office_Mode_Address_Pool (172.16.10.0/24) to VPN&amp;nbsp; Domain as part of the network.&lt;/P&gt;&lt;P&gt;I created a policy for the remote access.&lt;/P&gt;&lt;P&gt;Source: VPN users, VPN connection | Destination: MyLocalNetwork | VPN: RemoteAccess | Services:Any | Action: Accept | Track: Lag&lt;/P&gt;&lt;P&gt;set-up Check Point Endpoint security VPN Client to other laptop. add the site, and use username and password. connection successful&lt;/P&gt;&lt;P&gt;I can now access the company network while i' m outside. i can ping the 192.168.1.0/24 and 2.0/24 network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main issue, i can't access the application on the azure while im using vpn outside the office.&lt;/P&gt;&lt;P&gt;I tried to add the&amp;nbsp;CP_default_Office_Mode_Address_Pool (172.16.10.0/24) and the AzureVPN IP(10.x.x.x/16)&amp;nbsp; as part of MyLocalNetwork but the problems i encountered was the 2 sites are not able to access the Azure network 10.x.x.x/16 . The connection is disconnected.&lt;/P&gt;&lt;P&gt;i check the logs, Drop&lt;/P&gt;&lt;P&gt;172.16.10.1 was block to access 10.x.x.1 | encryption failure :&amp;nbsp;Security warning: received a cleartext packet within an encrypted connection&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN Feature: IKE&lt;/P&gt;&lt;P&gt;can anyone here will help me to resolved the issue.&lt;/P&gt;&lt;P&gt;appreciate your help.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2020 03:47:11 GMT</pubDate>
    <dc:creator>Sparks</dc:creator>
    <dc:date>2020-10-08T03:47:11Z</dc:date>
    <item>
      <title>Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98495#M9814</link>
      <description>&lt;P&gt;I'm using Checkpoint 5100&lt;/P&gt;&lt;P&gt;Firewall (IP 192.168.1.254) is connected to Azure via Route based with IP 10.x.x.x/16 with settings below;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings.PNG" style="width: 347px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8313i921D78A641BAFC07/image-dimensions/347x338?v=v2" width="347" height="338" role="button" title="vpn settings.PNG" alt="vpn settings.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings 1.PNG" style="width: 422px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8314i196C72289F2F8BCD/image-dimensions/422x296?v=v2" width="422" height="296" role="button" title="vpn settings 1.PNG" alt="vpn settings 1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn settings 2.PNG" style="width: 439px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8315i4200EC4CA8BB8D91/image-dimensions/439x269?v=v2" width="439" height="269" role="button" title="vpn settings 2.PNG" alt="vpn settings 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 2 Sites using def. Lan IP 192.168.1.0/24 and 192.168.2.0. Both sites are inter-connected via IPVPN/MPLS connection.&lt;/P&gt;&lt;P&gt;I create a network group called "MyLocalNetwork" which includes the following network (192.168.1.0/24, 192.168.2.0/24)&lt;/P&gt;&lt;P&gt;Source: MyLocalNetwork, AzureGW | Destination: MyLocalNetwork, AzureGW | VPN: AzureVPN | Services: Any | Action: Accept | Track: Lag&lt;/P&gt;&lt;P&gt;2 Sites can now access the Azure app via gateway of 1.0 and 2.0 going to Firewall (IP 192.168.1.254). All users of 2 Sites can access the apps via 10.x.x.x/16 just like local connection.&lt;/P&gt;&lt;P&gt;next&lt;/P&gt;&lt;P&gt;I configure the RemoteAccess Community by adding Gateway device to Participating gateway.&lt;/P&gt;&lt;P&gt;I created users and groups that i will add to Participant Users Groups at the VPN RemoteAccess Community.&lt;/P&gt;&lt;P&gt;I'm using Office Mode and use the Manual IP Pool which is the CP_default_Office_Mode_Address_Pool (172.16.10.0/24).&lt;/P&gt;&lt;P&gt;I add the&amp;nbsp;CP_default_Office_Mode_Address_Pool (172.16.10.0/24) to VPN&amp;nbsp; Domain as part of the network.&lt;/P&gt;&lt;P&gt;I created a policy for the remote access.&lt;/P&gt;&lt;P&gt;Source: VPN users, VPN connection | Destination: MyLocalNetwork | VPN: RemoteAccess | Services:Any | Action: Accept | Track: Lag&lt;/P&gt;&lt;P&gt;set-up Check Point Endpoint security VPN Client to other laptop. add the site, and use username and password. connection successful&lt;/P&gt;&lt;P&gt;I can now access the company network while i' m outside. i can ping the 192.168.1.0/24 and 2.0/24 network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The main issue, i can't access the application on the azure while im using vpn outside the office.&lt;/P&gt;&lt;P&gt;I tried to add the&amp;nbsp;CP_default_Office_Mode_Address_Pool (172.16.10.0/24) and the AzureVPN IP(10.x.x.x/16)&amp;nbsp; as part of MyLocalNetwork but the problems i encountered was the 2 sites are not able to access the Azure network 10.x.x.x/16 . The connection is disconnected.&lt;/P&gt;&lt;P&gt;i check the logs, Drop&lt;/P&gt;&lt;P&gt;172.16.10.1 was block to access 10.x.x.1 | encryption failure :&amp;nbsp;Security warning: received a cleartext packet within an encrypted connection&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN Feature: IKE&lt;/P&gt;&lt;P&gt;can anyone here will help me to resolved the issue.&lt;/P&gt;&lt;P&gt;appreciate your help.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 03:47:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98495#M9814</guid>
      <dc:creator>Sparks</dc:creator>
      <dc:date>2020-10-08T03:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98498#M9815</link>
      <description>&lt;P&gt;Does your Remote Access encryption domain include the Azure subnet?&lt;BR /&gt;This is required to route the traffic through the S2S VPN.&lt;BR /&gt;Further, the Azure side must know about the Office Mode subnet.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 04:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98498#M9815</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-08T04:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98500#M9816</link>
      <description>&lt;P&gt;Yes. the 172.16.10.0/24 is already added to domain as well as to azure side. but still no traffic coming from 172.16.10.0/24 going to Azure 10.x.x.x/16.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 04:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98500#M9816</guid>
      <dc:creator>Sparks</dc:creator>
      <dc:date>2020-10-08T04:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98542#M9817</link>
      <description>&lt;P&gt;Once the subnet of Azure is added to the encryption domain, the connection between internal/local connection from 2 sites will be disconnected.&lt;/P&gt;&lt;P&gt;The VPN Client still no connection and there's no traffic seen coming from 172.16.10.0/24 going to Azure 10.x.x.x/24&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 09:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/98542#M9817</guid>
      <dc:creator>Sparks</dc:creator>
      <dc:date>2020-10-08T09:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/122084#M9818</link>
      <description>&lt;P&gt;Hi Sparks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you find solution for that issue?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 17:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/122084#M9818</guid>
      <dc:creator>Juan_Brion_Garc</dc:creator>
      <dc:date>2021-06-24T17:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access VPN cannot access Azure Tunnel. But the local area can connect to Azure Tunnel</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/241750#M9819</link>
      <description>&lt;P&gt;Having the same challenge, have you been assisted on this one?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 08:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-VPN-cannot-access-Azure-Tunnel-But-the-local-area/m-p/241750#M9819</guid>
      <dc:creator>hnyandoro</dc:creator>
      <dc:date>2025-02-20T08:37:56Z</dc:date>
    </item>
  </channel>
</rss>

