CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-07
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default I'm stuck

Hi All,

I have a Smartcentre Server (NGXR60 HFA04, Win2k3)with an internal IP address. I have a module (SPLAT and NGXR60 HFA04) with an internal IP address. On the module object I have set the VPN link selection to use the external interface.

I have a SecureClient with Integrity 25 user licensed locally to the module.

When I dial in I can connect OK. When I then hang up and dial in again it says no IKE cert found (something like that). If I then got back to the VPN link selection and change it from use the external IP address to use interface based on topology and install the policy I can then dial in and connect OK, just the once, I then have to change the link selection again.

I have logged a call with our support folks and set them cpinfo from manager and module (they have access to our user centre, so I am guessing that they have looked and seen that all is licensed correctly) they have sent it on to Checkpoint and they have come back and said change the module IP address to the external interface. So;

I thought VPN Link Selection meant you didn't have to do that anymore ?

The license is set to the internal IP address can I simply change the module address and not touch the license because it is against an existing interface ?

Should I do this out of hours ?

Has anyone seen this before ?

Any ideas would be most welcome

Cheers,

George
Reply With Quote
  #2 (permalink)  
Old 2006-12-07
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: I'm stuck

Are you using central licensing or local licensing on the gateway? You should be using central.

With central, the gateway license is tied to the management server IP. If you need to change the gateway IP, you use SmartUpdate to detach the license from the gateway, change the IP and re-attach the license. No muss, no fuss, no Check Point involvement.

Ray
Reply With Quote
  #3 (permalink)  
Old 2006-12-08
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default Re: I'm stuck

Hi Ray,

Thanks for the reply. The SmartCentre server is local and the module is central.

The SecureClient license is local and installed on the module.

Cheers,

George
Reply With Quote
  #4 (permalink)  
Old 2006-12-08
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: I'm stuck

Try resetting the gateway IP in SmartCenter to the external address. It can really mess up VPNs if the internal address is used.

Ray
Reply With Quote
  #5 (permalink)  
Old 2006-12-12
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default Re: I'm stuck

Hi Ray,

I thought Link Selection cured this, oh well.

I have 4 interfaces on this box, the one that leads to internal is a 10.x.x.x address and this is the one that is assigned to the firewall. Can I just change it in the properties tab to the external IP and push a policy ?.

Or do I have to do more ?

Thanks,

George
Reply With Quote
  #6 (permalink)  
Old 2006-12-12
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: I'm stuck

Hi George,

I have changed the gateway object IP on a number of occasions and it hasn't seemed to cause any issues.

Regarding the the link selection - is your topology defined correctly on the gateway? It's the only thing I can think of that would cause topology based link selection to cause you issues.
Reply With Quote
  #7 (permalink)  
Old 2006-12-13
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 3
gfont96 has an average reputation (10+)
Default Re: I'm stuck

Hi All,

We fixed it. It turned out to be a corrupt IKE certificate in VPN. It's the only thing we could think of. We built a replica system and the thing worked as expected with original licenses, and yes, link selection works a treat.

The following will help even if it does say its for a different version, sk22752, it does give an error message when trying to recreate the cert, ignore it, and when you edit the fw-module object again it gets created no probs.

Thanks to you all....again !

Cheers,

George
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:02.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0