CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point UTM-1 Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-11
adrianw adrianw is offline
Junior Member
 
Join Date: 2007-10-07
Posts: 3
Rep Power: 0
adrianw has an average reputation (10+)
Default UTM-1 450

have FW's set up using 1 for trusted and 1 for DMZ (physically 2 seperate boxes) coming from a Nokia enviroment to bascially SPLAT on CP boxes. from trusted to DMZ use a hide NAT for VPN's example 172.16.1.50 would be hide NAT on DMZ for Trusted to use.

problem is VPN's not able to pass traffic, have used Manual NAT and Automatic NAT far end doesn't see any traffic, able to encrypt and create tunnel but not able to pass traffic. This is with several vendors as well as site to site from UTM box back to Nokia's at main site. Have manually added proxy-arp table in Linux portion this is how conditional NAT's are working for all devices terminating in networks. Is there anything different for standing up VPN's on the UTM boxes? Problem is with PIX/Concentrator/Cisco Routers with VPN modules and Other Check Points.
Reply With Quote
  #2 (permalink)  
Old 2008-05-14
gtrinidad gtrinidad is offline
Junior Member
 
Join Date: 2008-05-05
Posts: 3
Rep Power: 0
gtrinidad has an average reputation (10+)
Default Re: UTM-1 450

Quote:
Originally Posted by adrianw View Post
have FW's set up using 1 for trusted and 1 for DMZ (physically 2 seperate boxes) coming from a Nokia enviroment to bascially SPLAT on CP boxes. from trusted to DMZ use a hide NAT for VPN's example 172.16.1.50 would be hide NAT on DMZ for Trusted to use.

problem is VPN's not able to pass traffic, have used Manual NAT and Automatic NAT far end doesn't see any traffic, able to encrypt and create tunnel but not able to pass traffic. This is with several vendors as well as site to site from UTM box back to Nokia's at main site. Have manually added proxy-arp table in Linux portion this is how conditional NAT's are working for all devices terminating in networks. Is there anything different for standing up VPN's on the UTM boxes? Problem is with PIX/Concentrator/Cisco Routers with VPN modules and Other Check Points.
I have a utm-1 450 too, and i have the same problem... the vpn doesn´t work. Internet-148.x.x.x-Router Cisco-Nat-192.x.x.x-UTM Checkpoint. WHy not??? helpppp.....
Reply With Quote
  #3 (permalink)  
Old 2008-05-14
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 461
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: UTM-1 450

VPN works fine with the UTM-1 Appliances. The issue is in your configuration - I'd be checking whether you are disabling NAT within your VPN community, and/or if your NAT rules are affecting VPN traffic. Have a look in the logs at the xlate_src values of the packets that aren't working.
Reply With Quote
  #4 (permalink)  
Old 2008-06-20
adrianw adrianw is offline
Junior Member
 
Join Date: 2007-10-07
Posts: 3
Rep Power: 0
adrianw has an average reputation (10+)
Default Re: UTM-1 450

to update post with how this was fixed: had arp issue on Trusted FW could see Synch Ack on DMZ but only Synch so on DMZ fw made manual entry on arp table (created /etc/proxy-arp, pulls from rc.local so on reboot survives) to point to MAC address that Trusted FW has interface in. ran netstat -rn got IP address to go to perm and all is working now.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 05:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0