CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-18
compubear compubear is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 7
Rep Power: 0
compubear has an average reputation (10+)
Default allowing icmp redirect

Hello,

I'm running Checkpoint Express on linux, with NGX (R60) and have an issue whereby I _need_ to allow icmp redirect, I've already made a rule to allow ICMP type 5, however in smartview tracker I'm seeing that ICMP redirects are still being blocked.
Am I missing something, or is it just not allowed.

Regards.
Reply With Quote
  #2 (permalink)  
Old 2006-05-18
simon simon is offline
Junior Member
 
Join Date: 2005-10-12
Location: Germany
Posts: 6
Rep Power: 0
simon has an average reputation (10+)
Default Re: allowing icmp redirect

You need to enable the global kernel variable "fw_icmp_redirects".

You can do this by editing the file "$FWDIR/boot/modules/fwkern.conf".

Simply add the following line:
fw_icmp_redirects=1

Then reboot your system.

Regards,
Simon
Reply With Quote
  #3 (permalink)  
Old 2006-05-18
compubear compubear is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 7
Rep Power: 0
compubear has an average reputation (10+)
Default Re: allowing icmp redirect

Hello Simon,

Thanks, however I had already done that and rebooted my device. ICMP redirects unfortunately are still being blocked.

Regards.
Reply With Quote
  #4 (permalink)  
Old 2006-05-18
simon simon is offline
Junior Member
 
Join Date: 2005-10-12
Location: Germany
Posts: 6
Rep Power: 0
simon has an average reputation (10+)
Default Re: allowing icmp redirect

Hello compubear,

at this point some more details are needed to help you fixing the problem.

Should the firewall send icmp redirects, should it receive them, are you running a cluster, is it a secure platform linux or redhat?

Regards,
Simon
Reply With Quote
  #5 (permalink)  
Old 2006-05-18
compubear compubear is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 7
Rep Power: 0
compubear has an average reputation (10+)
Default Re: allowing icmp redirect

Hello Simon,

I'm running Redhat Enterprise 3.2.3-52, this is the latest software that came for our device which is a SecureGuard.

The Secureguard in our network is intended for VPN traffic to a remote office, and we do not wish to use it as a gateway (although it can definitely do it).

We have another gateway (Gateway2) which has a separate internet connection for our users.

At times however, our users may need to communicate with the remote office so what I did was add a static route on Gateway2 to redirect traffic intended for the remote office to go through the Secureguard.

However, with a simple ping, I'm getting in the region of 47% packet loss to our remote office, I'm also getting a fair amount of entries similar to the one below:
"Number: 20099
Date: 18May2006
Time: 17:31:01
Product: VPN-1 Pro/Express
Interface: eth0
Origin: sgvpn (192.168.0.254)
Type: Log
Action: Drop
Protocol: icmp
Source: sgvpn (192.168.0.254)
Destination: 192.169.0.10
Information: ICMP: Host Redirect
ICMP Type: 5
ICMP Code: 1
message_info: ICMP redirect packets are not allowed"
If however I do point the local machines (which are running windows XP SP2 by the way) I get no packetloss when I do a 10000 ping test and I can connect to the remote network with no problems whatsoever.

192.168.0.10 is a local machine, 192.168.0.254 is the Secureguard and 192.168.0.250 is Gateway2.

I can write a simple batch script which can add/delete the routes to the remote network on the machines, however, I needed a solution that was non intrusive as possible to our users.

Regards, and thanks much.
cbear.
Reply With Quote
  #6 (permalink)  
Old 2006-05-22
compubear compubear is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 7
Rep Power: 0
compubear has an average reputation (10+)
Default Re: allowing icmp redirect *sorted*

I had my fwkern.conf file in the wrong folder, put it in the correct one, rebooted my machine and everything is now sorted.

Regards,
cbear.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:49.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0