- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We are trying to switch to Unified Access Policy.
When connecting to SNX in Network Mode Only, third party users, lose their local network.
A lot of routes are prescribed on the PC.
There are no routing problems when working with Legacy Policy, but when switching to UAP, there is a route to two subnets with the gateway specified from the IP Pool of Issued Addresses.
Can you tell me why these routes are created? Maybe we missed something when configuring Unified Access Policy?
Are the networks in question included in the encryption domain?
No. Clients are connected via Mobile Access to SNX.
And once connected, they lose their local network.
Are you saying no because:
Whether it's one of the regular Remote Access clients or SNX in Network Mode, the routes received by the client will match what is configured in the Remote Access Encryption Domain.
This may not be the case in legacy mode, but in Unified Access Policy mode, this is definitely the case.
That is, in order to ensure that users do not lose their local network, network must be added to the remote access encryption domain in the gateway settings?
The routes injected to the remote access clients should match the Remote Access Encryption Domain settings.
It therefore must be removed, not added.
In the encryption domain we have the internal subnets 192.168.0.0 and 172.16.0.0.
If we select "All IP Addresses behind Cluster Members based on Topology information" these subnets will also be in the encryption domain.
Do you mean use the encryption domain without any subnets?
Or should we add the subnets to the exception in "Set Specific VPN Domain for Gateway Communities", just like in sk167000?
You need to modify the encryption domain so the subnets you don't want to inject to your remote clients are not included in the definition.
The approach mentioned in sk167000 should work for this case, though you don't necessarily need to use "any" here.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY