- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Team,
We have 14 public IP addresses bound to our WAN port.
The public IP of the wan is A.B.C.1.
We want to dedicated the IP A.B.C.2 for the remote access VPN. This IP (A.B.C.2) is not assigned to any internet.
We have performed the following change:
Device > Advanced > Advanced Settings >
- VPN Remote Access - Enable Visitor Mode on This Interface = A.B.C.2
Despite this configuration, the firewall is not responding to vpn requests from remote users.
I have performed the following test:
- With a tcpdump on WAN interface, I have observed that the gateway does not answer the ARP Requests related to the IP A.B.C.2
My question is:
Can we assign an IP does not belong to an external interface in the option "Device > Advanced > Advanced Settings > VPN Remote Access - Enable Visitor Mode on This Interface"?
Regards
Hi All,
I have received answer from the TAC:
Visitor mode is relevant only for configured interfaces on the appliances.
You can't establish VPN C2S to IPs which are not interfaces
Hi PhoneBoy
This is a migration from other firewall to checkpoint and there is a nat rule on the wan interface with https using by many partners: disable this feature is not suitable for the customer, that impact many users.
Hi Maarten,
Thanks for your help. This a SMB appliance (700) locally managed. I have seen the sk114531 related to your instruction and I will try this.
Regards
Constant NSAH
Hello,
I have tried sk114531 and the gateway answers the ARP Requests related to the IP A.B.C.2 but the VPN still failed.
I will contact TAC.
Hi All,
I have received answer from the TAC:
Visitor mode is relevant only for configured interfaces on the appliances.
You can't establish VPN C2S to IPs which are not interfaces
It seems to me it will be easier for you to change the main WAN IP to .2 and leave the .1 only for the NATs.
That way you don't have to deal with all the partners and the VPN keeps the same IP address.
Thank for your comment. This is a last solution that we plan to do. As I have written before, there is many services published on this IP, and these services are used by many partner.
What I suggested was to change only the main WAN address to A.B.C.2, which will enable you to use Remote Access VPN on that address.
You can keep the published pages and services (except VPN) on IP address A.B.C.1 or any other address of your range, provided you set the correct proxy ARP and NAT rules.
This seems to be the way to cause least impact on your partners and VPN clients.
The only affected services would be site-to-site VPNs, if you have any, which will have to move from A.B.C.1 to A.B.C.2, but I think it is better to make changes to site-to-site than client-to-site, specially if you don't have a DNS for that.
So:
No impact for published pages
No impact for VPN clients
Easy to fix impact on site-to-site VPNs.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY