Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend
Jump to solution

Domain objects in remote access vpn domain

Hey guys,

I really hope someone can confirm this for me, because I find it a bit confusing. Its reference to below post:

https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-remote-access-encryption-domain...

So, my colleague and I did it the same way for a client last week and worked like a charm, we added 2 domains in new group called exclusions_ and then added that group to RA vpn domain, pushed policy, tested after reconnecting to their VPN, no issues!

Then, we followed the same for another client, but was failing, could be the site, not sure. Then, we opened TAC case and were told this is NOT supported, to add domains to vpn domain and exclusions group is to exclude things, not include them, though not sure this is officially documented anywhere, at least that I was able to find.

Here is my logic about it...to me personally, does not matter what group is called, as long as it belongs to the vpn domain, there would be no reason not to work. To exclude something, from my experience, you would simply add group with exclusions.

Or am I missing this completelly?

 

Thoughts? 🙂

Tx as always!

Andy

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend

Issue fixed. It was the method using group that starts with exclusions_ that needed to be added to RA vpn domain, but appears was website issue.

Andy

View solution in original post

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

Documented here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
the_rock
Legend
Legend

I know that link, thats same one from the original post, but I dont see anywhere there stating that this is not supported.

Andy

0 Kudos
the_rock
Legend
Legend

Quick update. TAC gave us below sk, but Im not sure if it is applicable in this case, but maybe someone can confirm. Anyway, we will test this ourselves in customer's environment to see if we can get it working.

Andy

https://support.checkpoint.com/results/sk/sk142832

0 Kudos
the_rock
Legend
Legend

Latest update:

Confirmed with R&D that adding domains is indeed supported and what I attached proves it as well.

Andy

0 Kudos
the_rock
Legend
Legend

Issue fixed. It was the method using group that starts with exclusions_ that needed to be added to RA vpn domain, but appears was website issue.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events