- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi everyone,
Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.
Topo:
At the Mobile VPN, they have a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web related to Office365, which needs to automate route the traffic: client -> HQ -> O365.
Note: With endpoint devices VPN must route all traffic to HQ: endpoint -> HQ -> internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).
I had seen this sk: How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com), but seems like its opposite with my case.
Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?
Please help me.
Thanks & Best regards.
Hi everyone,
Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.
Topo:
At the Mobile VPN, they have a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web related to Office365, which needs to automate route the traffic: client -> HQ -> O365.
Note: With endpoint devices VPN must route all traffic to HQ: endpoint -> HQ -> internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).
I had seen this sk: How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com), but seems like its opposite with my case.
Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?
Please help me.
Thanks & Best regards.
Hi everyone,
Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.
Topo:
At the Mobile VPN, they have a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web related to Office365, which needs to automate route the traffic: client -> HQ -> O365.
Note: With endpoint devices VPN must route all traffic to HQ: endpoint -> HQ -> internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).
I had seen this sk: How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com), but seems like its opposite with my case.
Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?
Please help me.
Thanks & Best regards.
Just wondering, is this the case of customer wanting to assign different auth methods to different groups? If so, I dont believe thats possible as of yet. If I totally misunderstood, apologies.
Andy
Just wondering, is this the case of customer wanting to assign different auth methods to different groups? If so, I dont believe thats possible as of yet. If I totally misunderstood, apologies.
Andy
Because this is the usual use case: route everything except for Office 365.
To do what you're trying to do (route Office 365 traffic through the Remote Access VPN), see: https://support.checkpoint.com/results/sk/sk167000
Note that you might want to investigate Harmony SASE for this use case.
Because this is the usual use case: route everything except for Office 365.
To do what you're trying to do (route Office 365 traffic through the Remote Access VPN), see: https://support.checkpoint.com/results/sk/sk167000
Note that you might want to investigate Harmony SASE for this use case.
Ah, that sk, right.
Ah, that sk, right.
Hello,
if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with "o365_address_ranges" and if needed other networks as member.
Doing so, all traffic to o365 will be routed via the security gateway.
if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.
as therock mentioned, having multiple ... "VPN profiles" you might likely run into limitations.
Hello,
if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with "o365_address_ranges" and if needed other networks as member.
Doing so, all traffic to o365 will be routed via the security gateway.
if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.
as therock mentioned, having multiple ... "VPN profiles" you might likely run into limitations.