- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello,
We have a request from our customer to implement split tunnel solution for certain user/users. Currently they have full tunnel remote access VPN.
I've found sk167000 (https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...) tested it also in lab environment and it works great. But it's only applicable for a VPN community.
Is it possible to implement split tunneling somehow for a user group?
Thanks in advance!
Zsolt
in the global properties you set the "route all traffic to gateway" to "configured on endpoint client" for oth the secureclient mobile and endpoint connect options
on the gateway object you tick the box for "allow vpn clients to route traffic through this gateway" and you configure the remote access encryption domain for the split vpn users
if the end user connects once to the gateway, the setting to route all traffic to gateway will no longer be greyed out and the user can freely choose between full tunnel or split tunnel
you could create a new vpn package one for full tunnel users and one for split tunnel users and install accordingly, that way you don't have to teach them about the setting
download the tool from sk122574
i believe you need the setting "neo_route_all_traffic_through_gateway"
I believe below is what you are looking for:
Andy
I believe this option just defines which with authentication method can user authenticate on the VPN client.
Split tunneling is a global setting, unfortunately, so it applies to everyone.
That's what I thought. Thanks, PhoneBoy!
route all traffic to gateway (yes/no/decide on endpoint)
make the default in the trac.default file to route all traffic to gateway, but tell specific users to manually untick the checkbox in their client?
Sounds good. May I ask for an SK or example from where I can learn and test it?
in the global properties you set the "route all traffic to gateway" to "configured on endpoint client" for oth the secureclient mobile and endpoint connect options
on the gateway object you tick the box for "allow vpn clients to route traffic through this gateway" and you configure the remote access encryption domain for the split vpn users
if the end user connects once to the gateway, the setting to route all traffic to gateway will no longer be greyed out and the user can freely choose between full tunnel or split tunnel
you could create a new vpn package one for full tunnel users and one for split tunnel users and install accordingly, that way you don't have to teach them about the setting
download the tool from sk122574
i believe you need the setting "neo_route_all_traffic_through_gateway"
Thanks Jan!
Meanwhile I've found sk114882. Based on that and your help it works for me in lab environment.
In addition to your settings I've modified the ttm files:
In the test group file:
:neo_route_all_traffic_through_gateway (
:gateway (endpoint_vpn_route_all_traffic_through_gateway
:default (client_decide)
)
In the trac_client_1 file:
:neo_route_all_traffic_through_gateway (
:gateway (endpoint_vpn_route_all_traffic_through_gateway
:valid (false)
:default (true)
)
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY