- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Dear Checkpoint Community,
I am experiencing an issue with our VPN setup and would appreciate your assistance. The network topology is as follows:
Location 1:
Location 2:
There is a site-to-site VPN established between Location 1 and Location 2, allowing seamless connectivity between the servers and users in these locations.
Issue: Users in Location 1 and the servers in Location 1 can successfully ping/connect to the servers in Location 2 through the site-to-site VPN. However, remote access (RA) VPN users connecting to the Checkpoint firewall at Location 1 are unable to connect to the servers in Location 2.
Steps Taken:
Despite these steps, RA VPN users still cannot access Location 2 servers. I suspect there might be an issue with the routing or access rules specific to RA VPN users.
Questions:
Any guidance or suggestions would be greatly appreciated. Thank you in advance for your help!
I would say as long as vpn domains and rules are good, you should be fine. As far as troubleshooting, I would confirm the logs first, then maybe do some basic vpn checks, ie does it fail on phase 1 or 2? What do they see on the other side?
Andy
Hello @the_rock , Thank you for the response. please find attached logs screenshot for your reference.
Do you see any dropped logs about it? Based on what you sent, I cant really "decipher" why this fails.
Andy
Not able to see any dropped logs when I try to ping from RA User to location 2 servers, attached the screenshot.
Might be worth TAC case to check further, sorry, I dont work often with SMB : - (
The case is already open with the support team (SR Number: 6-0003950608) and has been for a few weeks, but they have not been able to assign an engineer yet.
Did you set the Remote Access Encryption Domain to include Location 2's resources?
This is done in VPN > Remote Access > Advanced
Click on the link in the sentence Local encryption domain is defined automatically according to topology...
Users will need to re-add the site to their client after this.
Hello @PhoneBoy,
I have added Location 2's resources to the Local encryption domain, but Remote Access users are still unable to access these resources. Please refer to the attached screenshot of the configuration and logs. As you can see, there are no drops.
Did the users delete and re-add the site on their end?
If so and this persists, you may need the TAC to investigate: https://help.checkpoint.com
Hello @PhoneBoy, yes, while troubleshooting, I deleted the site and reconfigured it from both ends, but the issue still persists. I have also raised a TAC case (Case #: 6-0003950608), but they have not provided a proper solution.
Keep us posted how it goes with TAC.
Andy
Sorry to say, but we are opting to use a third-party service for our VPN needs, as TAC has been unable to resolve the issue. We hope that the R82 firmware for SMB locally managed devices will address this issue.
Does anyone know when the R82 firmware for SMB firewalls will be released?
R82 for SMB is most likely next year (note R82 is not GA for regular Quantum Appliances yet).
SAML Support (something you mentioned in your SR) is actually planned for R81.10.15, which is currently in EA.
It's also not clear from the SR if you included the networks behind the TP-Link router in your Remote Access Encryption Domain.
This needs to be configured correctly for this to work.
Additionally, make sure the TP-Link knows to route the Office Mode addresses back to you (these are the IPs the clients will receive on connection).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 | |
2 | |
1 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY