Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
superd
Contributor

Checkpoint Endpoint and PAC file for Cloud Proxy

Jump to solution

Hi,

We are currently using Checkpoint Endpoint VPN client for remote access. Without split tunnelling - all traffic to GW.

We are now looking to implement a cloud proxy service by means of a PAC file.

With proxy PAC specified in client browser, we cant get it working with or without VPN conncted.

We essentially want to have PAC browsing available regardless of VPN connectivity.

Is this likely a matter of updating the client desktop policy, or are there some guidlines or settings I may have missed for this type of scenario?

Thanks.

Dave

0 Kudos
1 Solution

Accepted Solutions
superd
Contributor

Schoolboy error - encryption domain misconfigured!!

View solution in original post

0 Kudos
5 Replies
G_W_Albrecht
Legend
Legend

See Configuring Remote Clients to Work with Proxy Servers - Remote Access VPN R81.10 Administration Guide p. 200f

CCSE CCTE SMB Specialist
0 Kudos
superd
Contributor

Great will do, thanks. Ill let you guys know how it goes.

0 Kudos
superd
Contributor

Hi,

So, Ive reviewed the documentation around proxy servers, and enabled "Detect From IE" on client.

I have split tunnelling enabled, or send all traffic to GW set to "NO".

The ENC domain for the GW object looks ok, in that its only internall addresses / networks.

However, when I launch a browser tab, which should launch the PAC file connection, I see it being forced into the client VPN, and being dropped by the GW.

It seems the routing / VPN config is wrong here.

What would be the most likely issue here, or place to start investigating?

Am I correct to assume the desktop policy doesnt even come into play here, give the traffic is routing over the VPN?

0 Kudos
G_W_Albrecht
Legend
Legend

Contact TAC and get it resolved in a quick RAS.

CCSE CCTE SMB Specialist
0 Kudos
superd
Contributor

Schoolboy error - encryption domain misconfigured!!

0 Kudos