Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
DominusRex23
Participant

LAN‑Initiated Connections to Remote Access VPN Clients (Office Mode IP) Not Working

We are unable to establish LAN‑initiated connections to Remote Access VPN clients using Office Mode IPs. ICMP traffic from LAN to remote users is accepted and encrypted in the RemoteAccess community, but there is no reply from the remote users back to the LAN.

In SmartConsole we configured rules to allow traffic from the LAN server to the Office Mode IP pool, and logs confirm the traffic is encrypted and allowed. We also enabled “Enable Back Connections” in Global Properties, but the outcome remains the same. Disabling the internal firewall on the remote client did not resolve the issue.

Has anyone successfully configured LAN‑to‑Remote Access back connections? Is there a recommended Access Policy setup or directional match condition that allows LAN hosts to initiate traffic toward Office Mode clients while maintaining proper VPN enforcement?

0 Kudos
1 Reply
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Have you accounted for things like the default automatic NAT that is applied to the office mode address pool object & anti-spoofing etc?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events