- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am seeking advice how to configure Split/Full tunnel per user/user group. The connection to VPN is over SSL portal SNX extender.
Something like this.
FW-A
user group - A : full tunnel, no split tunneling
user group - B : split tunneling only
FW-B
user group - C : full tunnel, no split tunneling
user group - D : split tunneling only
environment is Multidomain with VSX and Maestro.
Thanks
could you please provide more details on the purpose of configuring split/full tunneling per user/user group in your SNX SSL portal setup?
Could you please clarify whether you are using the Unified Access Policy or the Legacy Policy for your SSL rulebase?
Typically, with SNX SSL connections, when using the Legacy Policy, full tunneling may not be necessary as access is restricted to the specific applications allowed in the rulebase. This setup usually ensures that routing is managed according to the applications rather than requiring split or full tunneling.
Purpose is sell it in the same way as other competitors services (PA,FG) whos have solution for that.
You nailed it with that statement, could not agree more.
Andy
Last time I asked TAC about it, they said it was not possible/supported.
Andy
For the full Endpoint client, you can do something like this: https://support.checkpoint.com/results/sk/sk114882
Not sure you can do this with SNX, though.
I thought so.
Probably there is no full tunnel / hub mode in SNX but you can follow sk32111 Configuring Different Encryption Domains for Different User Groups in SNX and try a "All Internet" Group as Encryption Domain to get a full tunnel for specific user groups.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY