CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Secure Remote Issues

I am trying to connect to a Edge device running 6.046. I have set up a remote site in the edge device and cannot make a connection via secure remote. I keep getting gateway not responding.

I am tryin to connect remotely from a public network and I put in the public IP address of the DSL router which then NAT's to a local address. I keep getting the response Gateway not responding.

DOes anyone in here have any expertise that may be able to help me out on this.

Thanks,
razorack
Reply With Quote
  #2 (permalink)  
Old 2006-09-27
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Secure Remote Issues

nat nat nat devils work...

set ur dsl gate in bridge mode and sing a song
Reply With Quote
  #3 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Re: Secure Remote Issues

abusharif,

I should have said that the DSL router forwards the traffic to the Edge device via a NAT'ed address of 192.168.1.5. DO you still think the NAT is an issue?

Thanks for your help,

razorack
Reply With Quote
  #4 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Re: Secure Remote Issues

I also am not seeing anything in our edge device logs that even shows a VPN connection but I do see alot of these entries when I try to connect via Secure Remote:

02062 27Sep2006 10:13:16 TCP 209.44.17.68 [SYN attack] 58956 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02061 27Sep2006 10:13:05 TCP 209.44.17.68 [SYN attack] 58901 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02060 27Sep2006 10:12:55 TCP 209.44.17.68 [SYN attack] 58857 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02059 27Sep2006 10:12:44 TCP 209.44.17.68 [SYN attack] 58778 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02058 27Sep2006 10:12:34 TCP 209.44.17.68 [SYN attack] 58641 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02057 27Sep2006 10:12:23 TCP 209.44.17.68 [SYN attack] 58488 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02056 27Sep2006 10:12:13 TCP 209.44.17.68 [SYN attack] 58367 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02055 27Sep2006 10:12:03 TCP 209.44.17.68 [SYN attack] 58190 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02054 27Sep2006 10:11:53 TCP 209.44.17.68 [SYN attack] 58066 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02053 27Sep2006 10:11:42 TCP 209.44.17.68 [SYN attack] 57960 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02052 27Sep2006 10:11:32 TCP 209.44.17.68 [SYN attack] 57854 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02051 27Sep2006 10:11:22 TCP 209.44.17.68 [SYN attack] 57784 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02050 27Sep2006 10:11:12 TCP 209.44.17.68 [SYN attack] 57748 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS)
02049 27Sep2006 10:11:01 TCP 209.44.17.68 [SYN attack] 57688 192.168.1.5 (VPN-1 Edge) 981 (SofaWare HTTPS
Reply With Quote
  #5 (permalink)  
Old 2006-09-27
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Secure Remote Issues

check that traffic that leaves ur securemote actually reaches the edge (under tools in edge iface or cli you can sniff traffic). What leaves ur client should reach the edges external interface, which is probably not happening atm.
Reply With Quote
  #6 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Re: Secure Remote Issues

Thank you will check that now.

razorack--
Reply With Quote
  #7 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Re: Secure Remote Issues

The sniffer produced a .cap file how do I view that file, never had to view a .cap file.

Thanks,

razorack--
Reply With Quote
  #8 (permalink)  
Old 2006-09-27
Porter Porter is offline
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: Secure Remote Issues

try with ethereal -> http://www.ethereal.com/
__________________
misery is optional
Reply With Quote
  #9 (permalink)  
Old 2006-09-27
justin.knox justin.knox is offline
Junior Member
 
Join Date: 2005-09-30
Posts: 23
Rep Power: 0
justin.knox has an average reputation (10+)
Default Re: Secure Remote Issues

Wireshark has superseded good ol' Ethereal. There's a recent version too.
Reply With Quote
  #10 (permalink)  
Old 2006-09-27
razorack razorack is offline
Junior Member
 
Join Date: 2006-09-20
Posts: 8
Rep Power: 0
razorack has an average reputation (10+)
Default Re: Secure Remote Issues

Thanks to all who answered, the answer was the bridging on the Netopia DSL router. That worked like a charm.

Thanks to all,

razorack
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0