Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
guiausechi
Participant

Configuring VPN Link Selection for Remote Access client

 

Hello people,

anyone need to run this sk

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

in environment the cluster and the IP was not directly linked to the VIP interface, a range ip, I have some NAT on this IP on high ports and works, but the request the remote access on port 80/443 I only see it coming, I don't see the cluster responding.

exemplo, my internet range is 192.168.0.0/24

member01.: 192.168.0.201
member02.: 192.168.0.202
vip: 192.168.0.254
IP I tried to atributed to link selection as per sk: 192.168.0.100 (static NAT work when I use)

 

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

You'll probably need a proxy arp if you set the Link Selection to an IP address that isn't associated with the gateway or an automatic NAT rule.
Where precisely are you observing the gateway "not responding?"

0 Kudos
guiausechi
Participant

Hello @PhoneBoy , 

yes, I had a proxy arp, this IP with static NAT work very well, but when I tried to follow the SK to have one IP only to Remote Access that doesn't the VIP, doesn't work

0 Kudos
Robert_M_Nubile
Explorer

Hello,

Did you check if there is any drop in this communication?

As this IP is not associated with the Firewall I think it will not match the implied rule, so maybe you need to create a rule to accept this traffic.

One more thing the you can check is recreate the site and see if it connects for the first time and fail in the second time. If so you will need some adjusts to fix it.

Kind regards, 

0 Kudos