> Source: [sk165777](https://support.checkpoint.com/results/sk/sk165777)

# sk165777 - Remote Access VPN clients successfully connect, receive Office Mode IP address, but are unable to access the internal resources

| Property | Value |
|----------|-------|
| Solution ID | sk165777 |
| Date Created | 2020-03-13 |
| Last Modified | 2026-04-13 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * VPN Client Connects to the Security Gateway and receives an Office Mode IP Address Range. User can not access internal resources.  
  Traffic is seen on the Security Gateway passing to and from the Office Mode IP Address Range with Zero drops.
* If the Client is connected for some Time (5 minutes or more), the traffic may start passing with no changes made.
* If SecureXL is turned off, traffic is now reachable to the destination either immediately, or after a re-attempt at testing traffic while still connected to the VPN. (NOTE: user re-connected to the VPN after SecureXL was disabled).
* On the external interface there are a lot of ARP requests for the Office Mode IP Address Range.

## Cause

This is caused by a incorrect Route configuration for the next-hop set for the Office Mode IP Address Range.  

**For example** **:**   
Office mode IP = 172.16.10.0/24  
Static-Route:  
172.16.10.0/24 nexthop interface eth7  
\*\*\* Note, eth7 in this example is the External interface.\*\*\*  

<br />

Other causes are:  

* The routing table includes a network that is included inside the Office Mode IP Address Range and is directed to a different interface than the Link Selection configured. (Example: 10.0.0.0/8 static-route leading internally when Office Mode is 10.40.20/24). This can cause Office Mode traffic to be mis-routed.
* There is a static route for the Office Mode IP Address Range itself pointing to the wrong interface.
* The Office Mode IP Address Range should not be part of any internal network Address Spoofing,

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
