- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
Currently, I'm in the process of POC Checkpoint FW + Harmony for a potential customer.
Topo:
At the Mobile VPN, they have a test case: when the Employee's Mobile connects VPN (using capsule app), no need to route VPN to HQ when accessing internet, surfing websites,... but only when they use an app/web related to Office365, which needs to automate route the traffic: client -> HQ -> O365.
Note: With endpoint devices VPN must route all traffic to HQ: endpoint -> HQ -> internet. (and I can't create more than 2 remote access community for endpoint and mobile, so can't customize individual VPN domains).
I had seen this sk: How to configure Split Tunnel for Office 365 and other SaaS Applications (checkpoint.com), but seems like its opposite with my case.
Does anyone have experience with this case, or can Checkpoint create a multi Remote Access VPN?
Please help me.
Thanks & Best regards.
Hello,
if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with "o365_address_ranges" and if needed other networks as member.
Doing so, all traffic to o365 will be routed via the security gateway.
if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.
as therock mentioned, having multiple ... "VPN profiles" you might likely run into limitations.
Just wondering, is this the case of customer wanting to assign different auth methods to different groups? If so, I dont believe thats possible as of yet. If I totally misunderstood, apologies.
Andy
Because this is the usual use case: route everything except for Office 365.
To do what you're trying to do (route Office 365 traffic through the Remote Access VPN), see: https://support.checkpoint.com/results/sk/sk167000
Note that you might want to investigate Harmony SASE for this use case.
Ah, that sk, right.
Hello,
if this use case applies to all remote users, you might use the solution stated in the sk mentioned using the group object "enc_domain" as normal group with "o365_address_ranges" and if needed other networks as member.
Doing so, all traffic to o365 will be routed via the security gateway.
if you have other use cases regarding this setup you might run into problems, as encryption domains can only be set once per RemoteAccess Community. And there is only one RemoteAccess Community at one Management Server.
as therock mentioned, having multiple ... "VPN profiles" you might likely run into limitations.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY