Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
the_rock
Legend
Legend
Jump to solution

Using updatable objects/domains in RA vpn domain

Hey guys,

Hope someone can confirm this for me. Customer has case with TAC about this and they were told its not supported, and though they asked for something stating so, they were never provided an sk or document indicating its not supported. 

What they want to do is add a domain or updatabje object to RA vpn domain, which in itself does work, but then remote users can NOT access the desired object by fqdn, only an IP address.

Not sure if below would apply or not...thoughts?

Mgmt is S1C R82 and gateways are cluster R81.20 jumbo 92.

Andy

https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-remote-access-encryption-domain...

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend

Official TAC answer, though customer did try exclusion_ approach, but no joy...o well, guess not supported : - (

Andy

********************

 

For Remote Access VPN, URLs are not supported in the encryption domain. The closest thing that you can use is updatable object in a group with exclusions:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C... 

Here is additional documentation: https://support.checkpoint.com/results/sk/sk131852

One other options is to use Mobile Access VPN and configure a Web Application:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Cont...

View solution in original post

0 Kudos
2 Replies
the_rock
Legend
Legend

FWIW, I asked the customer to create new group that starts with exclusions_ as a name and try, so they will let me know if that made any difference.

Andy

0 Kudos
the_rock
Legend
Legend

Official TAC answer, though customer did try exclusion_ approach, but no joy...o well, guess not supported : - (

Andy

********************

 

For Remote Access VPN, URLs are not supported in the encryption domain. The closest thing that you can use is updatable object in a group with exclusions:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C... 

Here is additional documentation: https://support.checkpoint.com/results/sk/sk131852

One other options is to use Mobile Access VPN and configure a Web Application:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Cont...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events