- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Remote Access VPN Reply Interface
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Remote Access VPN Reply Interface
Hello guys,
Just want to know if anyone had a problem with outgoing traffic reply for VPN Remote Access, i just found out that when you try to establish the VPN tunnel with Remote Access on checkpoint it tries to reply using the default route of the Gateway, even if you have two external interfaces it does not use the setting on IPSec link selection (Reply from the same interface) and because of this the VPN tunnel cannot be establish.
I tried to use PBR for this but it also didnt worked, and i tried to found out something related to this on support center but didnt found anything, i think this is by design.
Anyone have a clue how to solve this? I had changed the default route to the other ISP interface (The one used by VPN Remote) and it worked, but i cant let this configured becase the users use the other link for internet access.
- Tags:
- remote access vpn
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is by design according to this SK: Outgoing VPN Link Selection on a gateway with multiple external interfaces
Maybe you can use VSX to work around this limitation?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dameon,
Thank you for the reply, unfortunately we do not have an VSX. The way i manage to overcome this by design setting was doing a NAT to the other external interface, now the outgoing traffic works and goes to the same interface!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Hugo
Can you please provide to us more details concerning NAT configuration?
BR,
Kostas
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure,
Since this limitation its by design in the Checkpoint Gateway, i had to create an external NAT on my ISP router from the other external interface mapping to the VIP interface on the cluster, doing that i could create the remote access VPN connection, since this time the Inbound/Outbound traffic was using the same external interface.
This its not an workaround on the Checkpoint configuration, its only a workaround on our topology to bypass this limitation.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Hugo
Now it is clear.
Thank you
Kostas
