> Source: [sk115476](https://support.checkpoint.com/results/sk/sk115476)

# sk115476 - How to access an internal routed network (LAN behind LAN) via Client to Site VPN on an SMB appliance

| Property | Value |
|----------|-------|
| Solution ID | sk115476 |
| Date Created | 2017-01-11 |
| Last Modified | 2022-07-24 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1500, 1600, 1800, 910 |

## Solution

**How to access an internal routed network (LAN behind LAN) via Client to Site VPN on an SMB appliance**

Using the following topology for an example:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115476/sk1154761701110637.png)

**Models:** 600 / 700 / 1100 / 1400 / 1200R

**WAN (Public)** : 1.1.1.1

**LAN:** 192.168.10.0/24

**Behind the 192.168.10.0/24 LAN there is another network** (separated by another gateway / Router /L3 SW): 10.10.10.0/24

A user wants to access 10.10.10.0/24 resources while he is at home.

**Solution**

**Add the internal routed network (LAN behind LAN) and the Internal LAN to be Manually configured in the VPN options:**

1. Open the 'appliance UI \> VPN tab \> Remote Access \> Advanced \> "Local encryption domain is defined": choose "Manually" and add the Internal LAN (192.168.10.0) and the Internal Routed LAN (10.10.10.0).  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk115476/sk1154761701120526.png)

<br />

1. Connect the User to the Internal LAN resources via Clent to Site VPN.
2. When the C2S VPN Connection is established successfully the routing table will be pulled locally.
3. When user attempts to access the internal LAN and Internal Routed LAN resources from C2S VPN, he should succeed.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
