Remote Access VPN client ignoring link selection

Recently one of my colleague faced an issue whereby the users using Checkpoint remote access VPN behaving weirdly. The behaviour is:

  • Users accessing for the first time is able to connect from the wireless // LAN home broadband. Subsequently unable to.
  • Users accessing for the first time is able to connect from their mobile phone tethering. Subsequently able to
  • From the smart view tracker it showing users accessing from wireless / LAN home broadband is accessing to another public IP belonging to some other devices but not Checkpoint based on its link selection configuration

The solution is to perform sk32229 – Configuring VPN Link Selection for SecuRemote/SecureClient

This happened when apply_resolving_mechanism_to_SR attribute located in objects_5_0.C. is set to “FALSE”. This will cause the remote access VPN to ignore the link selection configuration and instead it may choose another IP address.

To fix it, set accordingly either to “TRUE” or by configure the IP manually for the remote access VPN based on the SK.

Cheers

Remote Access VPN client ignoring link selection