- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
Anyone knows why a security gateway would exclude its management IP address out of the RA VPN client's routing table?
Case in point, the RA VPN community encryption domain includes the whole 10.0.0.0/8 subnet, yet the 10.0.0.X IP address, which is the management IP address of the security gateway where the RA VPN is terminated, is not included in the connected RA VPN client's routing table. The RA VPN client is Check Point Mobile and uses IPsec to tunnel traffic.
Thank you
Hello,
I finally got this working, it took a while for CP support to provide a fix, although a bit complicated for such a simple need:
- automatic MEP topology must be disabled oin the gateway, based on sk78180 (it already was disabled in my case)
- disable MEP topology retrieval in the VPN client's configuration, sk92676 (different than the default setting)
Best regards,
Alexandru
I just checked in one of customers' environments and works fine, no issues. Can you see what is output of route print from user's machine?
Andy
Hi Andy,
Here is a snippet of a connected RA VPN client's provisioned routes. You can see that the routes exclude the specific 10.0.0.252 IP address (which is the MGMT address of the security gateway) from the rest of the routes within the 10.0.0.0/8 prefix. I cannot find any specific configuration for this behavior via SmartConsole, perhaps there might be some parameter I could ajust directly in the DB.
Best regards,
Alexandru
I dont really see anything specific, below is just referred to dns when people log in via RA.
Andy
Hello,
I finally got this working, it took a while for CP support to provide a fix, although a bit complicated for such a simple need:
- automatic MEP topology must be disabled oin the gateway, based on sk78180 (it already was disabled in my case)
- disable MEP topology retrieval in the VPN client's configuration, sk92676 (different than the default setting)
Best regards,
Alexandru
Thanks for the update! 👍
Location Awareness enabled, perhaps?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY