- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi, I currently have a full tunnel configuration for remote access users in my security blades, but I need to know if it is possible to make a split tunneling configuration where all the users' traffic go to Internet through the firewall except some specific public IPs.
I have been thinking about create an object group with exclusions, where I include the default network 0.0.0.0/0 and exclude the requested public IPs. The thing is that I am not sure if it would work when I select this group with exclusions in the Remote Access Encryption Domain, because I believe that users will still receive the default network and will ignore the excluded public IPs and send all the traffic to the firewall.
Do you know if is there a way to achieve what I am trying to do? Thanks!
I have tried it and it has worked fine. Thanks 🙂
It's such a shame this can't be done with FQDNs. We support customers with Pulse Secure and we are seeing customers more and more who want to allow Teams and other SaaS applications to break out locally but tunnel internet traffic through central datacentre for URL filtering. We all know the overhead of maintaining the network groups using IPs for these services rather than updateable objects or FQDN.
Scott
Hi Scott,
that´s more or less what the SK is covering... but for whole Office365. If you want just Teams, you might use the script mentioned there and edit it to just import the Teams IPs. (API output is sorted for that: https://endpoints.office.com/endpoints/worldwide - you might want to look for "serviceArea": "Skype")
FQDNs are also changing at M$ for the several services.. afaik it is not just "teams.microsoft.com" there are loads of redirects and so on... some are also changing from time to time. depending on load or other.. Although you can take the script and edit it for your needs... ie. you set somewhere a plain text file with all directly connectable networks and let the script parse that...
For updatable objects I am with you, would be good. The SK is doing something similar. Very basic but as far as i understood updatable objects are maintained at a similar way.. (at least i found somewhere text files with (more beautiful and better) parsed MS api outputs 🙂 )
Daniel
If you ask me, a much better solution is to do the URL Filtering on the endpoint, which we are offering now with Cloud-Managed SandBlast Agent and are expected to have with on-prem management in R81.
How would that help to just "untunnel" a couple of services with dynamic destination ips and urls, while everything else is still tunneled?
Or do you mean to change completeley to just tunnel internal networks and everything else is than filtered by SandBlast on the client?
Yes, tunnel only internal things across the VPN and do the filtering on the client for everything else.
As of R81.20 this is now supported with updateable objects: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY