- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Check Point experts,
Since the customer switched from Palo Alto to Check Point a year ago, they have been consistently dissatisfied with the SSL VPN functionality. Recently, they raised another feature that they previously achieved on PA — as stated in the subject: “Is it possible to assign specific routes to certain users or user groups?”
The customer provided me with a screenshot showing their previous configuration on PA. I’m unsure whether Check Point can implement this functionality, or if there are other Check Point products that can meet the customer’s needs.
I would appreciate any advice from the experts.
OK, I think I understand. In older versions (using what is now Legacy Mobile Access policy), the encryption domain is the set of authorised locations configured in the applications allowed to a user. When utilising the Unified policy setup, the users all get the encryption domain configured on the gateway.
This method of encryption domain per user group may still work to provide what you're after.
https://support.checkpoint.com/results/sk/sk32111
Which remote access client/method are they using for SSL VPN? If it's client based then I think we don't have anything other than the global encryption domain. If they're doing clientless SSL VPN via Mobile Access portal, then the closest thing we have is Native Applications that can allow access to specific network ranges per user.
I don't know if Harmony SASE provides anything along these lines.
Hi Emmap:
Thank you for your reply.
The customer has used both methods, but this requirement is mainly intended to be implemented by configuring it on clientless SSL VPN. Since the users for this requirement must connect in Network Mode to function properly, Application Mode is not being considered by the customer.
OK, so if I'm understanding this right, Native Applications will provide per-user access to specific hosts or subnets on specific services. See:
Hi Emmap:
I would like to provide additional context for this requirement. The users in question are the customer’s vendor partners, who want to be able to access their own local network’s internal services while connected to the customer’s VPN. However, since the customer’s VPN Domain is defined as 10.0.0.0/8, once the users connect to the VPN, their traffic is routed into the VPN network, preventing them from accessing their own local internal services.
OK, I think I understand. In older versions (using what is now Legacy Mobile Access policy), the encryption domain is the set of authorised locations configured in the applications allowed to a user. When utilising the Unified policy setup, the users all get the encryption domain configured on the gateway.
This method of encryption domain per user group may still work to provide what you're after.
https://support.checkpoint.com/results/sk/sk32111
Hi Emmap:
Thank you for providing the SK. I believe this should be able to address the customer’s requirement.
However, the customer is currently using a Unified Policy. If we want to apply the configuration described in the SK, will it be necessary to switch to a Legacy Policy?
Will making this adjustment affect users who are using the Endpoint Agent?
I think I will need to set up a LAB and also get assistance from TAC.
All in all, I really appreciate your suggestion.
I believe the configuration in the SK will apply to Unified Policy deployments, but I have not tried it so testing in a lab environment would be good if that's feasible. Let us know how you go with it!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 18 | |
| 7 | |
| 7 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY