- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- SSL Webapp
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SSL Webapp
Dear mates
I create one webapp on ssl vpn. The thing is that I use the SSL VPN to connect on internal local but the host is on Azure that I have another site to site VPN with the internal net.
It seems that I can not access the webapp this way.
Can you assist me?
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So you're trying to access a web application from your gateway that is only available from a site-to-site VPN?
What are you connecting to at the other end of the VPN?
Is it configured to allow traffic from the gateway itself as a source (i.e. as part of the Encryption Domain or equivalent)?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy, Thank you for the reply.
Yes, I'm trying to access through SSL vpn a host on azure that is connecting from a site-to-site.
It's machine that hosting a website.
Please note that with ipsec vpn, i can access the website.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is hosting the IPSec VPN at the Azure end?
And is it configured to allow encrypted traffic that originates from the gateway's external IP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, the VPN is hosting by the checkpoint appliance and the Azure virtual gateway object. Also i notice that when I'm trying to access the web from SSL VPN. I'm not getting any logs on my checpoint gw
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The connection is probably being allowed from the gateway itself via an implied rule.
However, the remote end must be explicitly configured to allow a connection from the gateway's external IP.
I don't remember what they refer to it as on the Azure side, but it would be equivalent to the Encryption Domain on the Check Point side.
Although this would not be required on the Check Point side since the gateway IPs are always included in the Encryption Domain without explicitly being configured.
