CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-06
Junior Member
 
Join Date: 2007-01-12
Posts: 10
Rep Power: 0
olasoji has an average reputation (10+)
Default PPTP from a client with Hide-NAT

I have NG AI R54.

PPTP connection to a VPN device from an internal client hiding behind the FW's public IP address does not work.

I have 2 rules to allow pptp services (pptp-tcp and gre) from internal to the VPN device and from the VPN device to the internal client.

All traffic relating to pptp and the devices in question were allowed. Also, there are no dropped packets from the log and yet the pptp connection has not been successful.

Will anyone know why this has not been working? I will appreciate any help please. Many thanks in advance

Last edited by olasoji; 2007-12-06 at 11:30. Reason: more details
Reply With Quote
  #2 (permalink)  
Old 2007-12-06
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: PPTP from a client with Hide-NAT

Do you see any drops using the PPTP host as the source?
Reply With Quote
  #3 (permalink)  
Old 2007-12-06
Junior Member
 
Join Date: 2007-01-12
Posts: 10
Rep Power: 0
olasoji has an average reputation (10+)
Default Re: PPTP from a client with Hide-NAT

Unfortunately no. There was no drop using the pptp host as source.

Cheers
Reply With Quote
  #4 (permalink)  
Old 2007-12-07
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: PPTP from a client with Hide-NAT

Update to NGX and under smartdefense enable the VPN Protocol enforcement for PPTP. This is a known issue and that is what needs to be done to make it work.
Reply With Quote
  #5 (permalink)  
Old 2007-12-31
Junior Member
 
Join Date: 2006-10-07
Posts: 24
Rep Power: 0
canghel has an average reputation (10+)
Default Re: PPTP from a client with Hide-NAT

Quote:
Originally Posted by olasoji View Post
I have NG AI R54.

PPTP connection to a VPN device from an internal client hiding behind the FW's public IP address does not work.

I have 2 rules to allow pptp services (pptp-tcp and gre) from internal to the VPN device and from the VPN device to the internal client.

All traffic relating to pptp and the devices in question were allowed. Also, there are no dropped packets from the log and yet the pptp connection has not been successful.

Will anyone know why this has not been working? I will appreciate any help please. Many thanks in advance
I might be wrong, but the only workaround is to use static NAT.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0