CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-14
zippie74 zippie74 is offline
Junior Member
 
Join Date: 2006-05-14
Posts: 4
Rep Power: 0
zippie74 has an average reputation (10+)
Default what does different Community ID mean?

Hi,

I have been attempting to setup DNS zone transfers from one side of a VPN to the other.

I am receiving the error : Different community ID, possible NAT problem (VPN Error Code 2)

I can open other ports across the VPN without problem, its only when I attempt to use port 53 (DNS) that i have this failure.

Can anyone explain to me what this error means?

Thanks for your help,

zippie74,
Reply With Quote
  #2 (permalink)  
Old 2006-07-06
spinex spinex is offline
Junior Member
 
Join Date: 2006-02-20
Posts: 3
Rep Power: 0
spinex has an average reputation (10+)
Default Re: what does different Community ID mean?

Maybe you would like to make sure u don't turn on NAT for your VPN tunnel. That might be a problem since DNS is UDP which is connectionless ?
Reply With Quote
  #3 (permalink)  
Old 2006-07-06
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: what does different Community ID mean?

DNS uses TCP to do zone transfers.
Reply With Quote
  #4 (permalink)  
Old 2006-07-06
dbedit dbedit is offline
Senior Member
 
Join Date: 2006-06-14
Location: The Netherlands
Posts: 153
Rep Power: 3
dbedit has an average reputation (10+)
Default Re: what does different Community ID mean?

Disable 'accept domain name over tcp' and udp in your implied rules under global properties.

Cheerz
Reply With Quote
  #5 (permalink)  
Old 2006-07-06
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 872
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: what does different Community ID mean?

To expand upon dbedit's response, this error usually is seen when traffic that you thought was going down the VPN in fact is not. It's commonly seen when an implied rule accepts the traffic. Since the implied rule is always before any of your rules and before any VPN rules, it can cause odd quirks like this.

Hopefully you do not really have those DNS implied rules active because they open up your internal network's DNS servers in a manner you probably did not intend. They used to be checked by default in 4.0, and I know they are un-checked in NG by default. BTW, with 4.0, I believe they could be used to touch any server on your internal network simply my using port 53 for something other than DNS.

If you do disable them, make sure you have other DNS rules in place or things are going to break...

Ray
Reply With Quote
  #6 (permalink)  
Old 2006-07-06
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 872
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: what does different Community ID mean?

"Since the implied rule is always before any of your rules and before any VPN rules,"

Actually you can change some of them to "before last" in which case they occur after all of your rules, but most of them are before any of your rules.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 04:00.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0