<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Corporate Access - Users to Data center (Network) Unsuccessful in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/187940#M986</link>
    <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;The problem was not with our configuration. ICMP was working fine, we raised a TAC ticket and they had to change the MTU size on the Harmony Connect cloud gateways which then resolved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chethan&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 11:05:23 GMT</pubDate>
    <dc:creator>chethan_m</dc:creator>
    <dc:date>2023-07-28T11:05:23Z</dc:date>
    <item>
      <title>Corporate Access - Users to Data center (Network) Unsuccessful</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184316#M982</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am practicing Harmony Connect on my Home lab and&amp;nbsp;&lt;SPAN&gt;I have setup the Harmony connect for corporate access for users to access the internal resources.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;I'm following the admin guide for deployment.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Installed Ubuntu Server - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Installed docker engine on the ubuntu server - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Created a data center on Infinity portal and copied the connecter command - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Installed the connector on the docker engine - Successful. -&amp;gt; Verified the IPsec VPN tunnels are successfully established between the cloud controller and the gateway (docker logs -f &amp;lt;connector-id&amp;gt; | grep -w tunnel) - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Created a trusted user/device and installed the harmony connect client on the user machine - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Both the secure network access and internet access are connected on the Harmony Connect App - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Created the Network Access Control polices for (any source -&amp;gt; internal n/w) and installed the policy - Successful.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Verified that bypass network doesn't overlap the internal n/w in focus - Successful. &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Traffic is sent via harmony connect virtual adapter towards its gateway on the connect client application (verified on wireshark) but the connection is not established,&amp;nbsp;and I do not see any traffic on the connector side towards the destination (Internal resource) as well - &lt;STRONG&gt;Unuccessful.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In my virtual environment. This is how the network is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Internet &amp;lt;--&amp;gt; VNET &amp;lt;interface1&amp;gt; Ubuntu Server Host/Docker [Connector] &amp;lt;interface2&amp;gt; &amp;lt;--&amp;gt; Ubuntu Web Server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Things I need to know is:&amp;nbsp;&lt;/P&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;Must the Docker and the Internal resources be on the same sub-network, or can it be on different network?&lt;/LI&gt;&lt;LI&gt;Should I point the gateway of my internal resources towards the docker interface or not?&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I will share any logs or screenshots if necessary.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Chethan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Harmony Connect" id="cloudguard-connect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Harmony Solution Family" id="harmony-family"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Harmony Remote Access VPN" id="remote-access-vpn"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 03:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184316#M982</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-06-20T03:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Corporate Access - Users to Data center (Network) Unsuccessful</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184369#M983</link>
      <description>&lt;P&gt;The answer to both is no as far as I'm aware.&lt;/P&gt;
&lt;P&gt;Different subnets can be used and the internal resources should not be using the docker/connector as their default gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 14:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184369#M983</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-20T14:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Corporate Access - Users to Data center (Network) Unsuccessful</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184377#M984</link>
      <description>&lt;P&gt;Thanks for the information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Clientless Corporate Application sites (HTTP &amp;amp; SSH) for the same destination are working without any problem. I'm facing issue with Network Access only. I don't know which configuration I'm missing out. Will update the same.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 18:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/184377#M984</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-06-20T18:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Corporate Access - Users to Data center (Network) Unsuccessful</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/187765#M985</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;1) Please check that you don't have network in bypass configuration for HC agent.&lt;/P&gt;
&lt;P&gt;Harmony Connect App &amp;gt; setting &amp;gt; Harmony Connect agent &amp;gt; Bypass destinations.&lt;/P&gt;
&lt;P&gt;2) You should also have traffic allowed in Network Access&amp;nbsp; policy.&lt;/P&gt;
&lt;P&gt;3) Check that you can proper connectivity mode for HC agent&lt;/P&gt;
&lt;P&gt;4) Check that network where connector is connected and all other networks you plan to reach are included in DC object.&lt;/P&gt;
&lt;P&gt;If it won't help please contact me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 19:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/187765#M985</guid>
      <dc:creator>Andy_P</dc:creator>
      <dc:date>2023-07-26T19:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Corporate Access - Users to Data center (Network) Unsuccessful</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/187940#M986</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;The problem was not with our configuration. ICMP was working fine, we raised a TAC ticket and they had to change the MTU size on the Harmony Connect cloud gateways which then resolved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chethan&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 11:05:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Corporate-Access-Users-to-Data-center-Network-Unsuccessful/m-p/187940#M986</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2023-07-28T11:05:23Z</dc:date>
    </item>
  </channel>
</rss>

