> Source: [sk41398](https://support.checkpoint.com/results/sk/sk41398)

# sk41398 - SecureClient does not encrypt traffic to the VPN Domain

| Property | Value |
|----------|-------|
| Solution ID | sk41398 |
| Date Created | 2009-04-19 |
| Last Modified | 2017-01-23 |
| Technical Level | General |

## Symptoms

- * Office mode is configured, but traffic leaving the SecureClient uses the physical interfaces IP address.

* If the SecureClient hosts, physical IP address is routable, then traffic sent to the VPN gateway is unencrypted.

* If Hub mode is configured then traffic to the encryption domain works.

* Unencrypted traffic from the SecureClient (since it is using a routable IP address) is dropped on the clean up rule.  

<br />

## Solution

In NGX R60 and above uses a new feature of using Remote Access Community Domain. A Remote Access Community is a type of VPN community created specifically for users that usually work from remote locations, outside of the corporate LAN. This type of community ensures secure communication between users and the corporate LAN.  

<br />

By default the setting is this community domain is set to use the VPN domain settings of the gateway. If one happens to configure specific networks in this community domain then it will override the VPN domain settings resulting in the above mentioned symptoms.

Once you add the correct network objects to the Remote Access Community Domain then remote users can connect to those networks only.

To get there click on Gateway \>Topology \> Set Domain for Remote Access Community.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
