CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-28
bcolemont bcolemont is offline
Junior Member
 
Join Date: 2007-11-27
Posts: 3
Rep Power: 0
bcolemont has an average reputation (10+)
Default VPN tunnel problem, could be a bug?

Hi all,

I don't know where to post this so I just post it here :)

We have a checkpoint 6.5 cluster with VPN tunnels,
if the device on the other side is not up, the checkpoint doesn't create a tunnel (what is normal)
If the other device comes up and there is traffic for that location, the checkpoint routes the traffic to the internet and, doesn't look if the tunnel is up or not.
So he only checks it once,...
Is there a command to delete those routing tables orso and is there a workaround?

Greetz,
Bert Colemont
Reply With Quote
  #2 (permalink)  
Old 2007-11-28
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 151
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: VPN tunnel problem, could be a bug?

I take it you mean R65 not 6.5???

Have you checked the tracker (logs) to confirm any errors?
Reply With Quote
  #3 (permalink)  
Old 2007-11-28
bcolemont bcolemont is offline
Junior Member
 
Join Date: 2007-11-27
Posts: 3
Rep Power: 0
bcolemont has an average reputation (10+)
Default Re: VPN tunnel problem, could be a bug?

Yes I mean 6.5, and nothing comes in the log,...

let me try to explain the problem again :


Client 1
192.168.1.1

FW1 cluster<--ipsec tunnel -----> OtherFW <--> Server1
10.0.0.1
Client 2
192.168.1.2


if client 1 pings before the tunnel is up, he gets a route to the dark holes of the internet

if client 2 pings when the tunnel is up, he gets a reply

if client 1 pings again, now when the tunnel is up he still lands in the black hole on the internet.

So client 1 is never ever getting routed correctly and client 2 does, in the rules are definded that all 192.168.1.0 network may connect to 10.0.0.1
We also tried to delete the rule and make it again, also tried to set client 1 specific on a seperated rule to allow it to 10.0.0.1 but nothing helps.
Only thing that helps is to bring down all clients in the 192.168.1.x network, reboot the FW cluster and start up the tunnel and then bring up the clients
Reply With Quote
  #4 (permalink)  
Old 2007-11-29
bcolemont bcolemont is offline
Junior Member
 
Join Date: 2007-11-27
Posts: 3
Rep Power: 0
bcolemont has an average reputation (10+)
Default Re: VPN tunnel problem, could be a bug?

nobody who can help me?
Reply With Quote
  #5 (permalink)  
Old 2007-11-29
lodown lodown is offline
Member
 
Join Date: 2006-05-05
Posts: 54
Rep Power: 3
lodown has an average reputation (10+)
Default Re: VPN tunnel problem, could be a bug?

In the InterOP firewall object, make sure their correct network is set as the encryption domain.
Reply With Quote
  #6 (permalink)  
Old 2007-12-26
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 109
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: VPN tunnel problem, could be a bug?

Hi

why your traffic is going to internet when the tunnel is down, I supose it should get dropped at firewall itself. Pl check the rule allowing this traffic to internet.
Reply With Quote
  #7 (permalink)  
Old 2007-12-26
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,593
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VPN tunnel problem, could be a bug?

This is a configuration problem somewhere. Check the routing on client 1, check the encryption domains of both peers.

From client 1, do a traceroute and see where it thinks the packets are going.
From the gateway you can do an:

fw monitor -e 'accpet (src=192.168.1.1 and dst=10.0.0.1) or \
(src=10.0.0.1 and dst=192.168.1.1) ;'

and see if the packets are going through the firewall.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:34.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0