CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-10
Junior Member
 
Join Date: 2007-07-03
Posts: 5
Rep Power: 0
ymhhou has an average reputation (10+)
Default VPN after Upgrade to R62

Hi Everyone, I just upgraded from R54 to R62 Everything went perfect vpns came backup up everything was great except one thing.

Secureclient when you login to the firewall works fine but it is not going out to our other vpns. Eg. You call into 10.0.1.x and you can ping everything fine, but when you want to goto 10.0.2.x which is a vpn connection with an edge device it doesn't work. It used to before the upgrade but now wont. On the edge device I get an error packet was encrypted and should not be. I have triple checked the setup according to the checkpoint docs.

Any ideas?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-07-10
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 268
Rep Power: 2
dantro has an average reputation (10+)
Default Re: VPN after Upgrade to R62

That's quite simple. The error message says it all.
The VPN-1 Edge appliance correctly receives an encrypted package, but it doesn't decrypt it. Instead it drops the package telling you that it expected unencrypted traffic. So there is something wrong with your encryption domain. Check which encryption domain is configured for your VPN-1 Edge and make sure that the address from the SecureClient User is included.

Best regards,
Danny Trommer
CCSA/CCSE/CCSE+
Reply With Quote
  #3 (permalink)  
Old 2007-07-11
Senior Member
 
Join Date: 2007-06-04
Posts: 1,095
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: VPN after Upgrade to R62

I am assuming that when you say Secure Client you are not talking about Secure Remote as you will need to have Office Mode enabled for this to work.

The easiest way to solve this is as follows.

Use the option to

Set Encryption Domain for Remote Access Community

Specify this as the normal encryption domain behind the gateway you Secure Client too as well as the network behind the edge device.

Set the normal encryption domain for the gateway to be the existing encryption domain and the Office Mode range that you use for Secure Client.

Ensure that the site to site VPN between the Edge and the gateway includes the Office Mode range in the security rulebase

Push the policy to the gateway and the Edge.

I set this up only yesterday with two Check Point gateways and worked straight away. Alot easier then faffing about with vpnroute.conf files
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:46.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0