CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-06-01
Junior Member
 
Join Date: 2009-05-26
Posts: 4
Rep Power: 0
henryvu has an average reputation (10+)
Default Route all traffic to gateway problem

Hello,

I am having a configuration problem with my CheckPoint device to use VPN. Basically, now I can use SecureClient to connect to the CheckPoint and access the local network behind the CheckPoint. However, the problem is that I would like to force all traffic from VPN client to go through gateway but I could not.

Below is the configurations I did
* in Global Properties.
route all traffic when connected
* in the Checkpoint object:
Enable Hub mode (Allow Secure Client to route traffic through this gateway)
Setup office mode to the group with all users

The error I got when I tried to connect from SecureClient was
- User xyz authenticated by FireWall-1 authentication.
- Gateway not responding
- Connection failed

Could any one tell me which problem I am having. Note that without selecting the option "Route all traffic to gateway" at the SecureClient, I can still connect to the Checkpoint.

Thank you.

Last edited by henryvu; 2009-06-01 at 21:39.
Reply With Quote
  #2 (permalink)  
Old 2009-06-02
Junior Member
 
Join Date: 2009-05-26
Posts: 4
Rep Power: 0
henryvu has an average reputation (10+)
Default Re: Route all traffic to gateway problem

It seems that now I can make it work. In particular, I can connect SecureClient with the option "route all traffic through gateway" on. The problem, however, is that when turning it on, I cannot connect to the Internet.

Could anyone help me
Reply With Quote
  #3 (permalink)  
Old 2009-06-02
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 1,649
Rep Power: 5
northlandboy has an average reputation (10+)
Default Re: Route all traffic to gateway problem

Do you have appropriate NAT rules in place?
Reply With Quote
  #4 (permalink)  
Old 2009-06-02
Junior Member
 
Join Date: 2009-05-26
Posts: 4
Rep Power: 0
henryvu has an average reputation (10+)
Default Re: Route all traffic to gateway problem

No setup for NAT on the checkpoint device

However, for the local network, I choose "Add Automatic Address Translation Rules" with option "Hide behind Gateway"
Reply With Quote
  #5 (permalink)  
Old 2009-06-02
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 1,649
Rep Power: 5
northlandboy has an average reputation (10+)
Default Re: Route all traffic to gateway problem

What about your SecureClient users though?

When they're connected, and trying to get to the Internet, take a look at your logs, see if the logs show their traffic passing, and see if it is being natted.
Reply With Quote
  #6 (permalink)  
Old 2009-06-02
Junior Member
 
Join Date: 2009-05-26
Posts: 4
Rep Power: 0
henryvu has an average reputation (10+)
Default Re: Route all traffic to gateway problem

I tested the following two cases at SecureClient on Window Vista

1. Chose both Office mode and Hub mode. In this case, I saw a lot of dropping messages with error "encryption fail reason: Packet is from physical IP address but Office Mode is active". According to sk30481, this error may be caused because the IP address of client is overlapping with the external or internal IP address of the Checkpoint. (Actually, the testing machine I used is in the same network with the Checkpoint).

2. Chose only Hub mode (without using Office mode). In this case, I got different error: "encryption fail reason: Received a cleartext packet within an encrypted connection". The suggestion to fix this problem is to use in Office mode.

Thus, I do not know what to do. Actually, I also tried to connect with SecureClient from a different network (at home). But, at home, I could not connect with Hub mode. Could you let me know whether there are some specific configuration steps that are necessary and I may miss.

Actually, the purpose of my setting is quite simply. I just want to setup and collect "encrypted" traffic from VPN users when they access Internet, and analyze that traffic for research purpose. This is the reason why I need to configure VPN to run in Hub mode (to get all incoming and outgoing traffic of VPN users encrypted).
Reply With Quote
  #7 (permalink)  
Old 2009-07-09
Junior Member
 
Join Date: 2009-04-19
Location: Australia
Posts: 23
Rep Power: 0
skdreams has an average reputation (10+)
Default Re: Route all traffic to gateway problem

Hello,

I was having the same problem, even though having all the NAT & allow rules in place. In the Gateway properties in SmartDashboard, Remote Access tab, you need to tick the box under Hub Mode Configuration "Allow SecureClient to route traffic through this gateway"
Double check your NAT & Allow rules just in case.
Make sure that the Gateway in your Primary Network knows how to get to the remote clients, i.e. through the firewall interface.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:15.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2