CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-17
Junior Member
 
Join Date: 2005-11-17
Posts: 3
Rep Power: 0
BWenson has an average reputation (10+)
Default Client Cannot Browse Internet While Connected

I have a handful of users, all using DSL, who once they connect to the Gateway using SecureClient(NG R56 Build 311) with Office Mode, they cannot browse the Internet.

They can ping a server by address, but not by name. Obviously some kind of DNS problem.

They are using Office Mode because we have a 192.168.1.x network internally.

The problem may be specific to Westell Versalink 327W modems. Haven't confirmed all but I know at least two users use them.

The Versalink is giving out a 192.168.1.x address.

Any suggestions?
Reply With Quote
  #2 (permalink)  
Old 2005-11-17
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

I don't think it's a problem with the modem or with the IP address that it's giving out. That's what Office mode is used for and from the sounds of it you can connect to your Internal network without a problem.

Are you using a desktop policy that the client downloads? It may be blocking DNS or traffic to the DNS servers that the customer has set on their client.

Do you have SecuRemote DNS configured? This is used if you want the client to use your internal DNS servers when they are connected. If you do have it set to use this, the client may be having difficulty getting to them.
Reply With Quote
  #3 (permalink)  
Old 2005-12-02
Junior Member
 
Join Date: 2005-11-17
Posts: 3
Rep Power: 0
BWenson has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

Quote:
Originally Posted by Lackie
I don't think it's a problem with the modem or with the IP address that it's giving out. That's what Office mode is used for and from the sounds of it you can connect to your Internal network without a problem.

Are you using a desktop policy that the client downloads? It may be blocking DNS or traffic to the DNS servers that the customer has set on their client.

Do you have SecuRemote DNS configured? This is used if you want the client to use your internal DNS servers when they are connected. If you do have it set to use this, the client may be having difficulty getting to them.
I'm kinda a noob on this stuff. I believe that DNS is configured but I'm not sure how to change it. It's definitely some type of DNS thing where the client can't resolve names. Just not sure how to fix it.
Reply With Quote
  #4 (permalink)  
Old 2005-12-02
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

I'm presuming that you have a desktop policy that the client downloads... what kind of outbound rules do you have for the client? Do you have one that allows DNS out from the client?
Reply With Quote
  #5 (permalink)  
Old 2005-12-02
Junior Member
 
Join Date: 2005-11-25
Posts: 17
Rep Power: 0
alienbaby has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

Sounds like a desktop policy issue.

Be sure to have Log turned on for all the Desktop Policies. Alert, if you want a copy for your management server.
Reply With Quote
  #6 (permalink)  
Old 2005-12-06
Junior Member
 
Join Date: 2005-11-17
Posts: 3
Rep Power: 0
BWenson has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

I'm sure it's a desktop policy issue like you all said. I can ping Internet IP addresses but names are not being resolved.

In my policy rules, I have DNS allowed to our internal DNS server from the VPNUsers group. But I'm guessing that our internal DNS server is not the location the client is sending DNS requests.

What type of rule do I need to allow DNS access outside of our network? Or am I off track?

Last edited by BWenson; 2005-12-06 at 15:01.
Reply With Quote
  #7 (permalink)  
Old 2005-12-07
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

Put in a rule that looks similar to the following...

Source > Destination > Service > Action
usergroup@any > Any > DNS > Accept

That should allow DNS out from your client when they are connected.
Reply With Quote
  #8 (permalink)  
Old 2005-12-07
Junior Member
 
Join Date: 2005-11-25
Posts: 17
Rep Power: 0
alienbaby has an average reputation (10+)
Default Re: Client Cannot Browse Internet While Connected

And be sure the remove the SecuRemote DNS object if you have created it. DNS should only be configured in the Office Mode section of the gateway in use.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:49.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0