CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


First, I hope you're all well and staying safe.
Second, I want to give a "heads up" that you should see more activity here shortly, and maybe a few cosmetic changes.
I'll post more details to the "Announcements" forum soon, so be on the lookout. -E

 

Results 1 to 6 of 6

Thread: Disable Split Tunelling

  1. #1
    Join Date
    2013-02-22
    Posts
    23
    Rep Power
    0

    Default Disable Split Tunelling

    Can anyone let me know how I can disable split tunnelling for our remote users using endpoint security client?

    I have seen a few articles on the Internet, but none of their suggested solutions work.

    Thanks

  2. #2
    Join Date
    2008-07-31
    Location
    Netherlands, Europe
    Posts
    1,147
    Rep Power
    16

    Default Re: Disable Split Tunelling

    In the global settings go to remote access, under this section you have Secureclient Mobile and Endpoint Connect, in both sections tick the box "Route all traffic to gateway" push policy and you are done.
    Now one addition, on the gateway object, under VPN Clients goto section Remote Access and select under Hub Mode configuration the option Allow VPN clients to route traffic through this gateway.
    Last edited by msjouw; 2017-09-12 at 13:43. Reason: small addition.
    Regards, Maarten.
    Triple MDS on R77.30, MDS on R80.10, VSX, GAIA.

  3. #3
    Join Date
    2013-02-22
    Posts
    23
    Rep Power
    0

    Default Re: Disable Split Tunelling

    Hi Maarten,

    Thanks for the reply. I have tried your suggestions, but it still does not work.

    Once connected, if I look at the routing table of a device connected via Endpoint Connect, the default route 0.0.0.0 is still pointing to the interface of the MiFi unit that I am using for the remote connection. There is a second route to 0.0.0.0 with a subnet mask of 128.0.0.0 point to the interface of the virtual adapter and I cannot get to the Internet (even pings to 8.8.8.8 fail although I can get to devices in our Remote Access domain).

    Is there anything else I need to do?

    - David

  4. #4
    Join Date
    2008-07-31
    Location
    Netherlands, Europe
    Posts
    1,147
    Rep Power
    16

    Default Re: Disable Split Tunelling

    You need to make sure that in the Gateway policy you allow and NAT traffic towards the internet with the source network that you have used for the Office Mode Pool.
    Regards, Maarten.
    Triple MDS on R77.30, MDS on R80.10, VSX, GAIA.

  5. #5
    Join Date
    2011-08-02
    Location
    http://spikefishsolutions.com
    Posts
    1,668
    Rep Power
    13

    Default Re: Disable Split Tunelling

    Quote Originally Posted by Dandm View Post
    Hi Maarten,

    Thanks for the reply. I have tried your suggestions, but it still does not work.

    Once connected, if I look at the routing table of a device connected via Endpoint Connect, the default route 0.0.0.0 is still pointing to the interface of the MiFi unit that I am using for the remote connection. There is a second route to 0.0.0.0 with a subnet mask of 128.0.0.0 point to the interface of the virtual adapter and I cannot get to the Internet (even pings to 8.8.8.8 fail although I can get to devices in our Remote Access domain).

    Is there anything else I need to do?

    - David
    The route is correct. Remember in routing most specific route always wins. Check point adds a bunch of slightly smaller routes to force traffic the correct way.

  6. #6
    Join Date
    2013-02-22
    Posts
    23
    Rep Power
    0

    Default Re: Disable Split Tunelling

    Hi Guys,

    Sorry for the late reply, but I was dragged into another issue yesterday and was not able to try anything with this.

    It all works fine now. Many thanks for your help and the explanation of the routing.

    - Dandm

Similar Threads

  1. Split DNS
    By WeDrillForOil in forum Check Point UTM-1 Edge Appliances
    Replies: 4
    Last Post: 2016-09-07, 20:55
  2. Replies: 1
    Last Post: 2015-03-27, 09:36
  3. Disable Split Tunneling for Certain Clients
    By catatonic in forum IPsec VPN Blade (Virtual Private Networks)
    Replies: 0
    Last Post: 2012-10-29, 01:41
  4. Reg. Split tunneling
    By sachden in forum SecureClient/SecuRemote
    Replies: 6
    Last Post: 2008-05-13, 19:01
  5. Disable Split Tunnel
    By elvinmj in forum SecureClient/SecuRemote
    Replies: 2
    Last Post: 2006-08-14, 03:52

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •