Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jyrbn
Participant

Remote Access VPN Clients has no Internet Access when routing through the Gateway

Hi, 

We are trying to configure Remote Access VPN on a Centrally Managed (Smart-1 Cloud) Spark 1600, when routing all traffic through the security gateway, remote access clients can ping and access Internal Networks but has no Internet access which is need to access our cloud resources. 

We have followed this sk but are still not successful https://support.checkpoint.com/results/sk/sk101239.

Any ideas on what we could check?




0 Kudos
9 Replies
G_W_Albrecht
Legend Legend
Legend

Did you configure this also in rule base ?

As written in https://sc1.checkpoint.com/documents/R80.10_andhigher/WebAdminGuides/EN/CP_RemoteAccessVPN_AdminGuid...

Create the access control rule in the Access Control Policy.

VPN routing traffic is handled in the Security Policy Rule Base as a single connection, matched to one rule only.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
jyrbn
Participant

Which part of the documentation you sent are you referring to?

0 Kudos
G_W_Albrecht
Legend Legend
Legend

See the included link !

Hub Mode for Remote Access Clients

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
jyrbn
Participant

Yup, we've already enabled hub mode for the clients. 
image (1).jpg
Whenever I enable VPN tunneling (Routing traffic through the gateway) on the client even my own internet connection becomes "No Internet Access". 

image (2).jpg

0 Kudos
G_W_Albrecht
Legend Legend
Legend

No, i am talking about the rule base - RA clients are restricted by the rule base that tells which networks they can access.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
jyrbn
Participant

Ah yes, we have also configured a rule for remote access clients. 

Screenshot 2025-04-24 164206.png
It's destination is currently set to ANY for testing purposes. 

0 Kudos
PhoneBoy
Admin
Admin

Do you see anything in the logs when the Remote Access client connects and attempts to communicate?

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Why would you use hub mode at all ? Seems you usually have your private internet connection, so using endpoint security would be safe in all situations; with hub mode, you have the TP GW only when connected thru RA VPN.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
jyrbn
Participant

Our remote access clients needs to access our cloud resources using the Public IP address of our GW because that IP address is the one authorized to access them. That's why we need to route all traffic of the remote clients thru our GW.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 20 May 2025 @ 11:30 AM (PDT)

    Las Vegas: Check Point Hybrid Mesh

    Wed 21 May 2025 @ 11:30 AM (MST)

    Tempe, AZ: Check Point Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events