- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello,
I’m new to the Check Point solution. I’ve started by reading the admin manual, but I couldn’t find an answer to my question, nor could I find relevant information in existing topics, partly due to the language barrier. Thank you for your understanding and for pointing me to the right resources if needed.
Here’s the issue I’m facing:
Currently, the remote access VPN works perfectly for users connecting from outside the corporate network.
However, we’ve encountered a problem recently. Some of our users who travel to a partner site cannot access the network because the partner site refuses to act as their ISP. After implementing the architecture (as shown in the attached diagram), we set up an IPsec tunnel with the partner site so that users can connect back to our network by setting up the VPN client on their devices and connecting to our gateway.
The problem is that the VPN domain for these users, which should be coming from the firewal external zone, is now originating from the internal zone, triggering anti-spoofing.
I considered adding the subnet assigned to the VPN clients in the interface topology and marking it as non-antispoofing. However, this apparently disrupts connectivity for external users connecting via the VPN, which is not acceptable.
I read somewhere that adding a second VPN domain to the default Remote Access community might solve the issue, but I’m not sure how to approach this.
Thank you in advance for your help, CheckMates!
Best regards,
Hey @KingMar
Just to make sure I understand this correctly...you are saying there is now S2S vpn tunnel between partner location and your corporate infrstaructure and that works okay? If so, then there would be no need for users to connect withvpn client. Now, if there are anti spoofing errors, I would ensure to maybe exempt those subnets from anti spoof checks on external interface (its under gw object in smart console, network topology tab).
If I misunderstood, happy to do remote and help.
Let me know.
Andy
Hello @the_rock ,
Thank you for your response.
To confirm, the IPsec S2S tunnel between the partner site and our infrastructure is functioning correctly.
However, the firewall hosting the IPsec tunnel is not the Check Point. Instead, the traffic is NATed from a VLAN of the second firewall (hosting the IPsec S2S tunnel with the partner site) towards our Check Point, which handles the client-to-site VPN for our remote users.
Additionally, the partner site provides only a secure zone dedicated to our users when they are on-site. It functions essentially as a secure access point without internet. For internet access (the goal), users must activate their VPN as usual. The traffic then flows through the IPsec S2S tunnel between the partner site and our second firewall, is NATed to the Check Point, and subsequently establishes the client-to-site VPN session. we need to make this process seamless and transparent for the users.
I hope this explanation clarifies the setup. Please let me know if you need further details or have any suggestions.
Best regards,
I will logically assume that this is split tunnel setup where people need to use their own ISP for Internet traffic? If thats the case, then it would "fall" onto wherever they are located for that part, if you will.
Andy
Hello Andy,
No, that’s not the case. The goal is to provide users with internet access exclusively through the VPN to ensure that traffic is secured and monitored effectively.
Let me know if you need more details about the setup.
Best regards,
But then, if thats the case, did you ensure that access is properly allowed through CP fw? Because sounds it would be full tunnel set up, so VPN site to site would not matter here.
Andy
Hi Andy,
The purpose of the IPSec tunnel is simply to connect the two sites. After that, users are required to establish a client VPN to access the internet. We do not want anyone who directly plugs in from the partner site to have unrestricted access to our resources.
Best regards,
Ok, thats fine, but maybe we are not on the same page here, as they say lol
Here is what Im trying to say and apologies if its not clear. To me, based on what you explained, it sounds like this is 100% full tunnel, meaning users would NOT use their own ISP to connect online, but rather once connected to VPN, their Internet connection would go through the firewall, correct?
If answer to that question is yes, then what I was implying in my last response is that you would need to make sure traffic is properly allowed via the rule base so they can do so.
Andy
To clarify, yes, the outbound internet rules are fine since users can already access the internet when connecting from home. The issue, as I mentioned earlier, is that the VPN tunnel drops after about 5 seconds when a user connects from the LAN, whether from my LAN or the VLAN at the partner's site. That’s the main problem we're facing.
Best regards
Okay, I get it now, sorry for misunderstanding on my part. Anyway, here is what I would suggest. I am with @PhoneBoy as far as disabling anti-spoofing (it would be a good test for the involved interface in question), BUT, I would also refer to below sk about it, since lots of people confuse anti spoofing and address spoofing, as those are 2 different things.
Andy
https://support.checkpoint.com/results/sk/sk115276
Unfortunately another important point from where my request to the community is that we have a contractual problem with the subcontractor, so I cannot see this sk.
I will try to see if I can get the agreement to deactivate the antispoofing momentarily just to test as mentioned by @PhoneBoy
Its not super important you cant see the sk, I just wanted to point out the difference between the 2. Anywho, if you can temporarily disable antispoofing, it would definitely help you eliminate that as a possible issue.
Andy
The actual error messages you're seeing (with sensitive details redacted) might help as would version/JHF level.
The only thing I can suggest is using an Office Mode pool that is NOT in your internal address space. 
Hi PhoneBoy,
Here is the error message: the IP pool address assigned to our client VPN is not used within the LAN. It is specifically designated for clients connecting via the VPN from their PCs. Additionally, we are using Office Mode.
We are running version 81.20 (up to date with Take 89).
Best regards,
Best regards
What does eth2-01 connect to?
I suspect the quickest fix for this is to disable Anti-Spoofing.
If you haven't already, I'd open a TAC case.
it is the interconnection between the checkpoint and the firewall Back, management does not want us to deactivate antispoofing
Not permanently of course, but just as a test.
Andy
Hello Sirs,
I have some updates to share. Today, I attempted to disable Anti-Spoofing, and here’s what I tried:
First, I simply disabled Anti-Spoofing (switched it to detection mode instead of prevention). Everything worked as expected! The VPN client was able to connect from both WAN and LAN and navigate the internet and the company network without any issues.
Secondly, I set Anti-Spoofing back to its default prevention mode and configured the network dedicated to the VPN client as specified in the "remote access" community settings in the interface topology. Specifically, I configured the LAN-side interface, applied the override to a specific network, and added this network to the pre-existing network group. The client was able to connect from the LAN without interruption, but was unable to perform any actions, as everything was blocked by the Anti-Spoofing feature.
I hope this information helps guide you in providing a solution.
Best regards,
Hello Sirs,
I would like to provide a clarification regarding my previous message.
In the second part, where I reactivated Anti-Spoofing in prevention mode and configured the network dedicated to the VPN client, it did not work, whether internally (LAN) or externally (WAN) of course.
Please let me know if you need any further information.
Best regards,
So it failed with anti spoofing disabled?
Andy
Since the issue is with Anti-Spoofing, disabling it will resolve the issue.
To get this working correctly with Anti-Spoofing, you're going to have to engage with the TAC for proper troubleshooting.
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | 
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY