- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
We use the Mobile Access Blade for connecting into our systems and we also use a PACFILE for internet access.
Once a user has connected onto the MAB, if they untick the PACFILE on IE, then they can get to websites that would be blocked.
Ie - PACFILE would stop access to File Sharing sites, but a user can uncheck the PACFILE and then access File Sharing sites whilst still connected to the MAB.
I believe this is related around "Route all traffic"/"Split tunneling"
I found this article but as we are R80.30 I am not sure it applies:
Does anyone know how I fix this issue?
Thanks
You mean that you do use a proxy for internet access ? Then why can the clients disable the proxy at all ?
Says R77 and above
Versions listed mention R80.x but not R80.30 which I suspect is as it hasn't been updated since 23-Oct-2018 ie before R80.30 released.
That would then force all traffic up the VPN to the Check Point Gateway as opposed to relying on the fact that the Proxy is seen as reachable via the Gateway.
That way if disable the PAC when connected to the VPN would still force the traffic over the SNX tunnel.
Did you try sk101239: Route all traffic from Remote Access clients, including internet traffic, through Security... yet ? You may also need sk122854: "You are disconnected, please login again" pop-up appears in SNX window.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY