CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-13
Junior Member
 
Join Date: 2005-11-13
Posts: 2
Rep Power: 0
gold01 has an average reputation (10+)
Default Checkpoint NG site VPN HTTP proxy traffic

Have a hub site with proxy server inside lan and site to site VPN with a branch office, users can ping the proxy server from branch office across the VPN. But when they to browse the internet with proxy settings of the proxy server, the web browser displays no web pages. From the TCPDUMP it shows the proxy server is passing the packets to the firewall to be returned to the branch office. Any ideas what is going on?

Last edited by gold01; 2005-11-13 at 13:55.
Reply With Quote
  #2 (permalink)  
Old 2005-11-14
Junior Member
 
Join Date: 2005-11-11
Posts: 23
Rep Power: 0
jrdld has an average reputation (10+)
Default Re: Checkpoint NG site VPN HTTP prpxy traffic

Can the clients resolve Internet names via DNS? If not, that might be the problem. You might think that the proxy would be the one doing all the resolution of website names, but I've found that you can have problems if the clients cannot also resolve the names.

JR
Reply With Quote
  #3 (permalink)  
Old 2005-11-14
Junior Member
 
Join Date: 2005-08-19
Posts: 14
Rep Power: 0
Claer has an average reputation (10+)
Default Re: Checkpoint NG site VPN HTTP prpxy traffic

@jrdld : I had this problem only with old Netscape 4 browsers. We looked for the problem a long time. Pages were print ok with IE and not with Netscape.
I didn't have the problem with recent browsers.

@mankua: If your proxy is binding on a port with HTTP type traffic (advanced button in port properties), it can be the problem. If it's the case, try to create a new port without this analyse. Otherwise, do you have anything in your logfiles that could help us determining the cause of your problem ?
Reply With Quote
  #4 (permalink)  
Old 2005-11-16
Junior Member
 
Join Date: 2005-11-13
Posts: 2
Rep Power: 0
gold01 has an average reputation (10+)
Default Re: Checkpoint NG site VPN HTTP proxy traffic

The bluecoat proxy server handles all the DNS queries. They are working.

The problem seems to between the checkpoint Firewall and Bluecoat. Local users have no problems browsing the Internet via the Bluecoat proxy, but the branch office connected via VPN through the ChecKpoint Firewall do not work. But you can see packets on the TCPdump of the firewall.

It seems like when connections are made to the proxy from branch office via the VPN ok, cos the logs on the bluecoat confirm this but when requests are made they get lost in the Firewall somewhere and the firewall logs show nothing.
Reply With Quote
  #5 (permalink)  
Old 2005-12-12
Member
 
Join Date: 2005-08-30
Location: Perth, Australia
Posts: 72
Rep Power: 4
intehnet has an average reputation (10+)
Default Re: Checkpoint NG site VPN HTTP prpxy traffic

maybe set HTTP next proxy in global properties -> firewall-1 -> security server.
I'm dealing with a similar issue at the moment and i am about to try this..
__________________
///M
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:40.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0