- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am working on a specific requirement with Endpoint security VPN E84.40 clients. I read the admin guide in order to enable SDL and location awareness (Global properties>Endpoint connect). It contains a group with our internal IP addresses.
SDL is enabled on the client. Now when these users connect over an external network the SDL pops up which is good. But when the user comes into office the client pops up to connect on VPN again, as I understand client need to recognize that host is in a internal network and give a bypass on VPN client.
I have a network with many locations linked by MPLS links and this problem happens just in locations connected on my Datacenter by MPLS, when I connect directly on my LAN on my DataCenter it no happen.
I raised a ticket with CP TAC and receive the answer that is necessary to be connected directly on the same network than my gateway, but it is not clear for me, because my locations is connected by MPLS but have access to firewall directly.
Maybe there is a configuration missing in some point.
What settings are you using?
Hi PhoneBoy,
I have enabled the SDL on my client and configure "network location awareness" with my network range 10.0.0.0/8.
In the remote sites, it is connecting to the gateway via the internal interface or via the external interface?
Hi PhoneBoy,
In remote sites, we have an MPLS connecting with my DataCenter, in this case we are connecting with the internal interface, but I don´t have a specific configuration for that, on my client, I just configure my external IP when creating a profile.
The only configuration that I have to inform what is my internal LAN is on "location awareness".
Have you confirmed traffic to the gateway's external IP is in fact traversing the MPLS?
Yes, in this case, the client can´t reach the gateway´s external IP and it is correct because he is on my LAN, in my mind the client when connected on the first time on VPN need to receive the topology and the information about my internal range and based on this information don´t request to connect when receive one ip from my internal range.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY