CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-14
whennessey whennessey is offline
Junior Member
 
Join Date: 2007-09-13
Posts: 1
Rep Power: 0
whennessey has an average reputation (10+)
Default Can't access new domain through Securemote

Hi;

My company recently added a new domain and we have appended the dns on tcp/ip and while connected to the company LAN we can get to the new domain sites (.com and also OWA HTTPS:) but when not connected directly to LAN (external wireless, Broadband, etc.) we get a cannot find server or DNS error in internet explorer. If I uncheck the Securemote protocol or turn off the Checkpoint Securemote service I can access them fine. Is this needing DNS entries for the domain on the VPN/Firewall server??

Any help is greatly appreciated.
Bill
Reply With Quote
  #2 (permalink)  
Old 2007-09-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 355
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Can't access new domain through Securemote

I'd advise you to test further.

Try doing just name resolution on the Client PC, check if DNS works. I'm guessing it actually works, but routing is the problem.

If DNS works, then check how routing for the IPs used would work with SecuRemote, it might be that if you really are on the lan the routing is fine, but, if you come via the VPN it has problems. Office mode should give you the same results as from the LAN.

You could also alternatively use NAT hide on inbound SecuRemote connections, but that isn't "as clean".

Last edited by MarioL; 2007-09-14 at 08:17.
Reply With Quote
  #3 (permalink)  
Old 2007-09-17
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Can't access new domain through Securemote

I presume that you mean when coming in via VPN when you say not connected to the LAN but external wireless/broadband and that is the SecuRemote/Secure Client connecting in.

Is the new domain included in the encrypton domain by IP address, also if using Office Mode then only looks at one dns domain, ie

*.mydomain.com

This allows

hq.mydomain.com
branch1.mydomain.com
branch2.mydomain.com

etc

but not

*.mydomain.com
*.mydomain2.com

etc

You can however use SecuRemote DNS Servers for multiple DNS Domains to get around this.

Hope this is clear
Reply With Quote
  #4 (permalink)  
Old 2007-09-17
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 155
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: Can't access new domain through Securemote

As mcnallym says at the end, I've used the Secure Remote DNS servers, but all comms had to be done by the fully qualified domain name...


i.e Server1.uk.inet

not just Server1
Reply With Quote
  #5 (permalink)  
Old 2007-09-17
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 123
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Can't access new domain through Securemote

Go to Policy >Global Properties >Remote Access >Vpn Advanced and set the SR/SC behavior while disconnected to sent in the clear.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0