CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-12
Junior Member
 
Join Date: 2006-05-22
Posts: 28
Rep Power: 0
cheungtony has an average reputation (10+)
Default VPN user looped into heartbeat network

Just spot that if a VPN user is using the same network address with heartbeat segment (i.e. 192.168.x.x) , they cannot route to internal network properly after authentification but receive server not responding message, apart from changing the heartbeat segment to an uncommon address, could I make heartbeat network totally transparent from firewall ?

BTW, office mode is not used since we may need to upgrade the VPN client to SecuClient instead of using SecuRemote. Any suggestion ?
Reply With Quote
  #2 (permalink)  
Old 2007-03-14
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: VPN user looped into heartbeat network

Quote:
Originally Posted by cheungtony View Post
could I make heartbeat network totally transparent from firewall ?
There's no such thing as "totally transparent" because the cluster members need to know which network to use for sync.

The problem could be either that Firewall is seeing SecuRemote traffic as violating Anti-Spoofing or SecuRemote is trying to route traffic to cluster member's Sync Interface IP...

Check the logviewer and see which cluster IP responds, you will need to turn off DNS resolution so that the object isn't displayed and the IP is. You should see the request from the client go to the cluster VIP and then see one of the cluter member's IP in the response, it may or may not be natted to the cluster's VIP address (most likely not). Verify that its not using the sync network. Verify that the topo definition for the sync interface(s) on the cluter is listed as "Sync" and not a combo.

Either way you should see some kind of drop in the logs as to why. If you have the other "cluster anti-spoofing" feature turned on, it may be dropping traffic and not logging it. Otherwise per-interface anti-spoofing drops should display in the logs normally.

Quote:
Originally Posted by cheungtony View Post
BTW, office mode is not used since we may need to upgrade the VPN client to SecuClient instead of using SecuRemote. Any suggestion ?
This is why Office Mode was invented. :) The easiest and quite painless solution is to change the sync network...
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 05:00.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0