- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Prevent route learning over VPN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Prevent route learning over VPN
Dear Guy!
I am having a rather confusing issue that when the client connects to VPN remote access it automatically adds some routes, when I show route print via CMD on windows client.
How to turn off this automatic route learning?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By design, all networks specified in the Remote Access encryption domain are sent to the client.
The only option is to remove such networks from the encryption domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By design, all networks specified in the Remote Access encryption domain are sent to the client.
The only option is to remove such networks from the encryption domain.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you mean the networks I use for Remote Access Communities?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thats right, so as Phoneboy had said, its whats present in vpn domain specifically used for remote access ONLY. You can easily modify that via gateway (cluster) object in smart console, network management -> vpn domain, then edit it there, save, install policy, test. Just have clients disconnect/reconnect after policy is pushed.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am pretty positive what @PhoneBoy said has been the same way since the beginning of Check Point.
Andy
