- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Mates
We have currently migrated our vpn to Check Point, and everything seems fine. For that, in the IPsec VPN in Global Properties, the link selection is set to "Statically NATed IP".
Since we have some internal resources that requires vpn access, we do not wish to let users connect to the public IP in order to access internal resources. So, we wish to let internal users connect with the internal IP of the Check Point firewall.
Can this be accomplished? or we can only connect to the vpn using the statically NATed address?
When I try to connect to the vpn using an IP of the internal interface of the firewall, it connects, but after few minutes, if you check the VPN Properties on the endpoint, it goes back to the public IP.
Thanks in advance
I have been fighting with a similar issue, already event open case in TAC
Customer had on 77.30 cluster 2 entry points configured for remote VPN
The External Interface (ip configured on Main IP) where users connect to normally and a secondary Internal interface connected to a Dedicated LAN (with other router as next hop)
On the secondary interface side the customer uses a 3rd party client that connects normally and all works fine on 77.30.
After upgrade to R80.20 the 3rd party client stopped working, as this is not supported we are trying out Checkpoint VPN client.
The Checkpoint VPN client does not work on either version, on R77.30 it connects 1 time and then defaults back to the Main IP.
Exactly the behavior described on this SK discussed here.
I followed the Admin Guide and configured under IP_RESOLUTION_MECHANISM = topologyCalc - Calculate the IP address used for the VPN tunnel by network topology based on the location of the remote peer
This does not work same effect.
Did i understand correctly the admin guide ? this should enable the client to connect to the correct interface.
Is there a way to define a static connection ip for the SITE on the Client Trac.defaults?
There has to be a way to connect over more then 1 interface. (Secure remote connects and all works until the customer disconnects, the client changes the SIte ip also and client needs to change it manually)
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY