- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Is It possible to connect a host from a VPN si...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is It possible to connect a host from a VPN site to site to a VPN client IP (R80.20)?
Hi, I have only one VPN cluster - Check Point (80.20).
There are site to site and cliente to site VPNs in this cluster.
Is It possible to connect a host from a VPN site to site to a VPN client?
When the source tries, It drops with message:
"Routing outside encryption domain not enabled for this client"
4 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have certainly done this in the past where the clients are paid for clients with the OfficeMode.
Had to create a rule allowing the connection from the Internal networks to the OfficeMode Network. That rule does not have any VPN specified.
Any Firewall on the VPN Client needed to allow the connection from the Internal Networks as well.
Had to create a rule allowing the connection from the Internal networks to the OfficeMode Network. That rule does not have any VPN specified.
Any Firewall on the VPN Client needed to allow the connection from the Internal Networks as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will also need HubMode enabled on the Gateway that connecting too.
Separate Remote Access VPN Encryption Domain
Main Encryption Domain should include the Office Mode Network hence why need to use seperate Encryption Domain for Remote Access.
Site to Site VPN's should make sure that they see the Office Mode as part of the Site to Site VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Make sure to setup the VPN topology for remote access including the remote network at the 3rd party. Next to that you need to allow the traffic by a rule.
Also have the 3rd party include the Office mode network in the vpn topology for your end.
Also have the 3rd party include the Office mode network in the vpn topology for your end.
Regards, Maarten
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See sk94071: Cannot access Remote VPN client from Internal host for the needed configuration steps !
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
