- CheckMates
- :
- Products
- :
- Harmony
- :
- SASE
- :
- Harmony Connect Branch route exclusions
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Harmony Connect Branch route exclusions
Excluded routes can be set for the device agent in Harmony Connect to cover internal subnets so they do not route to the Harmony Gateways, Check Point also adds exclusions for a list of destinations (see SK170299) for the likes of YouTube which also go direct and not to Harmony Gateways.
To replicate this routing functionality for a branch (where I may have guest users or we elect to turn off the client) I can add other, more specific IPSec routes on the branch device for the known internal subnets, but how are the Check Point exclusions (like YouTube) catered for? The traffic would route up to the Harmony Gateways as they follow the default gateway.
Ray
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe we can only manage the application specific exclusions on the client itself.
For branch office devices, it would have to be configured on the device itself (subject to what it allows).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe we can only manage the application specific exclusions on the client itself.
For branch office devices, it would have to be configured on the device itself (subject to what it allows).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, that makes sense when I configure the routing set up of the SDWAN device. I think the SK should be updated to add a note about this and to alert people to the risk of some apps not working as alluded to in the SK.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like a good suggestion.
Recommend leaving specific feedback on the SK.