CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-27
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default VPN Tunnel Utility - Bug?

Can someone confirm a bug in R65 for me?

I am a frequent user of the VPN Tunnel utility and had need to use it yesterday. What I found was not the utility I know and love, but something totally useless and unusable instead.

On R60 (HFA_04):
In expert mode, type: 'vpn tu'
1) Pick an option - let's say 4 - List all IPsec SAs for a given peer (GW) or user (Client) then hit enter
2) Hey look, it's asking for an IP address and pauses
3) Type in the IP, hit enter
4) A list is generated for that peer IP and then you get 'press any key to continue'

On R65 (HFA_02):
In expert mode, type: 'vpn tu'
1) Pick an option - let's say 4 again to keep it consistent - List all IPsec SAs for a given peer (GW) or user (Client) then hit enter
2) Hey look, it's asking for an IP address and keeps on going, never giving you the opportunity to put in an IP - it goes straight to press any key

Any listing generated shows ALL IPSec SA's. Consequently, it is impossible to delete any phase 1 or phase 2 keys using the utility for any peer since the IP input is passed over.


Well, at least this is what happens on my system (SPLAT R65 HFA_02, Active/Passive HA Cluster)
__________________
There's no place like 127.0.0.1
Reply With Quote
  #2 (permalink)  
Old 2007-11-27
stuartgreen stuartgreen is offline
Member
 
Join Date: 2005-09-15
Posts: 65
Rep Power: 3
stuartgreen has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

confirmed... =(


I get the same thing for options 4 / 8. Also on R65 / SPLAT / HFA_02.


Very odd isn't it...
Reply With Quote
  #3 (permalink)  
Old 2007-11-27
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: VPN Tunnel Utility - Bug?

I'm running R65 HFA01 in the lab. I'll test this later and post the results.
Reply With Quote
  #4 (permalink)  
Old 2007-11-27
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

I can confirm this only with option 3),5) and 7) at SPLAT R65 HFA_02
Reply With Quote
  #5 (permalink)  
Old 2007-11-27
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

I can confirm that I get the same issue with R65 HFA-02 running on both
SPLAT and Nokia IP380
Reply With Quote
  #6 (permalink)  
Old 2007-11-27
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

Quote:
Originally Posted by dsb.nepo View Post
I can confirm this only with option 3),5) and 7) at SPLAT R65 HFA_02
Now that's interesting. What platform? Although, I wouldn't think this would matter. I'm guessing that the menu system for this is from the VPN-1 module, which is why the Nokia was similarly affected.

So, we're waiting on confirmation for HFA_01 and R65 base.

I opened a ticket with my VAR/NOC today and they also confirmed. I'll have them submit it.

Thanks! This is one of those things they'll probably turn out a hotfix for in no time...
__________________
There's no place like 127.0.0.1
Reply With Quote
  #7 (permalink)  
Old 2007-11-28
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: VPN Tunnel Utility - Bug?

It's confirmed, this is the SK #sk33393. Check Point Support offers a HotFix to resolve this issue. You need to open a ticket to get it.
Reply With Quote
  #8 (permalink)  
Old 2007-11-28
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

Quote:
Originally Posted by RobertGraham View Post
It's confirmed, this is the SK #sk33393. Check Point Support offers a HotFix to resolve this issue. You need to open a ticket to get it.
That sk listing is for R60A and only options 5 and 6. I would be surprised if they have a hotfix for this version yet.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #9 (permalink)  
Old 2007-12-05
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: VPN Tunnel Utility - Bug?

CheckPoint will have a hotfix for this very soon but they have provided a workaround in the meantime.

To traverse the error, enter the option number followed by a space and then the IP you are targeting, then hit enter. The command line menu will accept, store and use both parameters as valid input.

I will be declining the hotfix as a standalone since this is an acceptable solution and I don't like installing standalone hotfixes unless I must.
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:59.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0