CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-31
Junior Member
 
Join Date: 2006-07-21
Posts: 7
Rep Power: 0
redster has an average reputation (10+)
Default SNMP source interface

Hi all,

Is there a way to edit the source IP address that checkpoint uses for sending SNMP traps?

I have a simple VPN tunnel between 2 offices both running checkpoing R54.
From office A i would like to monitor the SNMP traps sent by checkpoint from office B.

I have allowed the SNMP traffic to be encrypted across the VPN but here is the problem

1 From office A SNMP-READ to internal interface of Firewall@Office B is sent ok.
2 From Office B SNMP-READ is decrypted ok
3 Office B firewall then sends back SNMP-TRAP encrypted but as External IP for its source
4 Office A sees this SNMP-TRAP as a source that is the External IP address from Firewall B not the internal address and rejects the packet.

So can i edit the policy to make Firewall B send out as its internal interface address?

From OfficeA i also have a VPN tunnel setup with an office running a PIX and on the PIX i can use
"MANAGEMENT ACCESS INSIDE" and "SNMP-SERVER HOST a.b.c.d INSIDE" to achieve the effect of sending using the internal interface IP address.

Last edited by redster; 2006-07-31 at 08:41.
Reply With Quote
  #2 (permalink)  
Old 2006-07-31
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: SNMP source interface

Redster, what platform are you running on? With IPSO, you can set the "Trap PDU Agent Address"

If you're using SPLAT, then there should be a way to do it - look for the documentation for the net-snmp package.

I'm not quite sure I follow the flow between steps 2 and 3 though - if I send an snmp-get to a node, I don't expect to receive a trap - I just expect to see and snmp response. Traps are for asynchronous events, like a link failure.

I think you would only get a trap in response to an snmp-get if you had the wrong community string, and it responded with an snmp authentication failure.
Reply With Quote
  #3 (permalink)  
Old 2006-07-31
Junior Member
 
Join Date: 2006-07-26
Posts: 13
Rep Power: 0
dondma has an average reputation (10+)
Default Re: SNMP source interface

You can alwways exclude the SNMP ports being used in the advanced VPN community properties. But then you will need to create an allow rule for this.

D
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:38.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0