Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
VannessChen
Explorer
Jump to solution

Remote Access VPN – Can specific routes be assigned to particular users?

Hi Check Point experts,

Since the customer switched from Palo Alto to Check Point a year ago, they have been consistently dissatisfied with the SSL VPN functionality. Recently, they raised another feature that they previously achieved on PA — as stated in the subject: “Is it possible to assign specific routes to certain users or user groups?”

The customer provided me with a screenshot showing their previous configuration on PA. I’m unsure whether Check Point can implement this functionality, or if there are other Check Point products that can meet the customer’s needs.

messageImage_1755128782778.jpg

 

I would appreciate any advice from the experts.

0 Kudos
1 Solution

Accepted Solutions
emmap
Employee
Employee

OK, I think I understand. In older versions (using what is now Legacy Mobile Access policy), the encryption domain is the set of authorised locations configured in the applications allowed to a user. When utilising the Unified policy setup, the users all get the encryption domain configured on the gateway. 

This method of encryption domain per user group may still work to provide what you're after. 

https://support.checkpoint.com/results/sk/sk32111

 

View solution in original post

(1)
7 Replies
emmap
Employee
Employee

Which remote access client/method are they using for SSL VPN? If it's client based then I think we don't have anything other than the global encryption domain. If they're doing clientless SSL VPN via Mobile Access portal, then the closest thing we have is Native Applications that can allow access to specific network ranges per user. 

I don't know if Harmony SASE provides anything along these lines.

VannessChen
Explorer

Hi Emmap:

Thank you for your reply.


The customer has used both methods, but this requirement is mainly intended to be implemented by configuring it on clientless SSL VPN. Since the users for this requirement must connect in Network Mode to function properly, Application Mode is not being considered by the customer.

0 Kudos
emmap
Employee
Employee

OK, so if I'm understanding this right, Native Applications will provide per-user access to specific hosts or subnets on specific services. See:

https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Content/Topics-SNX-Admin-Guide/...

0 Kudos
VannessChen
Explorer

Hi Emmap:

I would like to provide additional context for this requirement. The users in question are the customer’s vendor partners, who want to be able to access their own local network’s internal services while connected to the customer’s VPN. However, since the customer’s VPN Domain is defined as 10.0.0.0/8, once the users connect to the VPN, their traffic is routed into the VPN network, preventing them from accessing their own local internal services.

0 Kudos
emmap
Employee
Employee

OK, I think I understand. In older versions (using what is now Legacy Mobile Access policy), the encryption domain is the set of authorised locations configured in the applications allowed to a user. When utilising the Unified policy setup, the users all get the encryption domain configured on the gateway. 

This method of encryption domain per user group may still work to provide what you're after. 

https://support.checkpoint.com/results/sk/sk32111

 

(1)
VannessChen
Explorer

Hi Emmap:

Thank you for providing the SK. I believe this should be able to address the customer’s requirement.

However, the customer is currently using a Unified Policy. If we want to apply the configuration described in the SK, will it be necessary to switch to a Legacy Policy?

Will making this adjustment affect users who are using the Endpoint Agent?

I think I will need to set up a LAB and also get assistance from TAC.
All in all, I really appreciate your suggestion.

0 Kudos
emmap
Employee
Employee

I believe the configuration in the SK will apply to Unified Policy deployments, but I have not tried it so testing in a lab environment would be good if that's feasible. Let us know how you go with it!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events