CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
roadrunner roadrunner is offline
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 4
roadrunner has an average reputation (10+)
Default Secure Client and Overlapping Encryption Domains

Secure Client and Overlapping Encryption Domains
As far as SecuRemote is concerned, any given IP address can only be a part of one encryption domain. If you have one site that has an encryption domain added into your SecuRemote client and then try and add another site that has an encryption domain with any overlap (i.e. they contain similiar IP addresses), you will get this error.

In the following case, the error will also occur:


Site A manages firewalls F and G
Firewall F has an encryption domain X and is marked exportable
Firewall G has no encryption domain, but it is marked exportable
One or more interface on firewall G is in encryption domain X
SecuRemote always adds the firewall's interfaces to the encryption domain. Since firewall G is in F's encryption domain, there is an overlap in encryption domains. Olaf Selke suggests you can remove the offending interface definition from the firewall object and things should work normally, though you might have some problems with anti-spoofing.

FireWall-1 itself supports overlapping encryption domains only if the encryption domains overlap completely (i.e. you're using a Multiple Entry Point configuraton).

If you have multiple firewalls with partially overlapping encryption domains and you need to use them, you can either upgrade to SecuRemote? build 4100 and later (which allows for enabling or disabling encryption domains at will).

-- PhoneBoy - 02 Apr 2004


FAQForm
FAQs.Class: SecureClientFAQs
FAQs.OS:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:52.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0