Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hugo_Frauches
Contributor

Remote Access VPN Reply Interface

Hello guys,

Just want to know if anyone had a problem with outgoing traffic reply for VPN Remote Access, i just found out that when you try to establish the VPN tunnel with Remote Access on checkpoint it tries to reply using the default route of the Gateway, even if you have two external interfaces it does not use the setting on IPSec link selection (Reply from the same interface) and because of this the VPN tunnel cannot be establish.

I tried to use PBR for this but it also didnt worked, and i tried to found out something related to this on support center but didnt found anything, i think this is by design.

Anyone have a clue how to solve this? I had changed the default route to the other ISP interface (The one used by VPN Remote) and it worked, but i cant let this configured becase the users use the other link for internet access.

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

This is by design according to this SK: Outgoing VPN Link Selection on a gateway with multiple external interfaces 

Maybe you can use VSX to work around this limitation?

Hugo_Frauches
Contributor

Hello Dameon,

Thank you for the reply, unfortunately we do not have an VSX. The way i manage to overcome this by design setting was doing a NAT to the other external interface, now the outgoing traffic works and goes to the same interface!

Konstantinos_In
Contributor

Hello Hugo

Can you please provide to us more details concerning NAT configuration?


BR,

Kostas

0 Kudos
Hugo_Frauches
Contributor

Sure,

Since this limitation its by design in the Checkpoint Gateway, i had to create an external NAT on my ISP router from the other external interface mapping to the VIP interface on the cluster, doing that i could create the remote access VPN connection, since this time the Inbound/Outbound traffic was using the same external interface.

This its not an workaround on the Checkpoint configuration, its only a workaround on our topology to bypass this limitation.

0 Kudos
Konstantinos_In
Contributor

Hello Hugo

Now it is clear.

Thank you

Kostas

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events