CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-01
Junior Member
 
Join Date: 2006-11-01
Posts: 3
Rep Power: 0
gmoore has an average reputation (10+)
Default SecureClient & LAN issues

Hello all,

We are having an issue with SecureCLient. The SecureClient can connect from home fine and we can access everything but after we connect from home and bring it back to our corporate LAN we have issues browsing some Intranet sites and accessing some shares. There are no desktop policies defined and we are obviously not connected through SecureClient when on corporate. Our nslookups are not working either for the sites. It seems to be blocking DNS to our Intranet sites . As soon as I stop the Secureclient services I am able to browse the Intranet again.

We are using NGX R60 HFA1.

Any help would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 2006-11-01
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 3
Acidio has an average reputation (10+)
Default Re: SecureClient & LAN issues

It sounds like some sort of policy is installed - somehow. What does the SecureClient diagnostics tool show?

There is also an option you can set in the userc.c which should help
allow_clear_in_enc_domain (false) is the default. Change to true and restart sec client.

Also defining a default policy that allows communication to the encryption domain will help.

AllUsers@xxx as the source or destination (depending on the direction of the rules) will define rules that get applied to a default policy of your choosing.

Rules would look like this:

Inbound Rules
SRC = EncryptionDomainObject
Destination = AllUsers@EncryptionDomainObject
Service = Any
Action = Accept
Track = Log

Outbound Rules would have the source an destination swapped around.

These rules should allow traffic to pass to and from the clients OK and will only apply when the users are withing the encryption domain
Reply With Quote
  #3 (permalink)  
Old 2006-11-01
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 3
Acidio has an average reputation (10+)
Default Re: SecureClient & LAN issues

Oops, should clarify....

AllUsers@Any defines the default rules that get applied to a policy not
AllUsers@xxx

So to protect your users fully when on of off the network, you'll also need to define the clean up rules...

EG
Any, AllUsers@Any, Any, Drop, Log
AllUsers@Any, Any, Any, Drop, Log

The rules I mentioned in the previous post will allow traffic to pass to and from the clients/encryption domain while the policy is loaded.

Sorry for any confusion
Reply With Quote
  #4 (permalink)  
Old 2006-11-02
Junior Member
 
Join Date: 2006-11-01
Posts: 3
Rep Power: 0
gmoore has an average reputation (10+)
Default Re: SecureClient & LAN issues

Acidio, Thanks!!! Adding the True in the userc.c seemed to fix it. I will now look into the rules.
Reply With Quote
  #5 (permalink)  
Old 2006-11-02
Junior Member
 
Join Date: 2006-11-01
Posts: 3
Rep Power: 0
gmoore has an average reputation (10+)
Default Re: SecureClient & LAN issues

I tried to create the rules you stated but I could only do the outbound. It does not let me put users in the destination.

Source: allusers@encryption_domain
Destination: encrytpion_domain
VPN: remote access
Service:any
Track:log

This one was ok but when I went to reverse it, it won't let me add users to destination....
Reply With Quote
  #6 (permalink)  
Old 2006-11-03
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 3
Acidio has an average reputation (10+)
Default Re: SecureClient & LAN issues

Are you adding the rules under the Desktop Security tab?

There are two sections - Inbound rules and Outbound rules. Don't forget these are rules that will be pushed to the client machine, so inbound rules means traffic inbound to the client machine and outbound means traffic leaving the client machine. These rules aren't enforced by Firewall-1

Secure client is all about protecting your network and remote client machines via rules enforced by secure client on the remote user machine.
Reply With Quote
  #7 (permalink)  
Old 2007-02-09
Junior Member
 
Join Date: 2005-12-14
Posts: 19
Rep Power: 0
giulitn has an average reputation (10+)
Default Re: SecureClient & LAN issues

Hi all,
I have the same problem
CP cluster of NGX R60 HFA2
Secure Cleint NGX R60 build 191

Into the corporate LAN they are not able to connect at all; they receive the IP address from the DHCP server but they are not able to connect to any server or either to logon to Domain Controller.
I've modified to true the parameters allow_clear_ in enc_domain ed allow _send_clear_text_when_disconnect but it doesn't work.
The only way is to unbind the SC from tha LAN NIC.

Any idea?


Thanks
Reply With Quote
  #8 (permalink)  
Old 2007-02-09
Junior Member
 
Join Date: 2005-12-14
Posts: 19
Rep Power: 0
giulitn has an average reputation (10+)
Default Re: SecureClient & LAN issues

Sorry the CP is R60 HFA_04 , hotfix 604

Thanks
Reply With Quote
  #9 (permalink)  
Old 2007-02-13
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 3
Acidio has an average reputation (10+)
Default Re: SecureClient & LAN issues

Is the IP range you're assigning to the Sec Client users routed back to your gateway?
Reply With Quote
  #10 (permalink)  
Old 2007-02-14
Junior Member
 
Join Date: 2005-12-14
Posts: 19
Rep Power: 0
giulitn has an average reputation (10+)
Default Re: SecureClient & LAN issues

Hi,
thanks for your reply.
The answer is no, they are not routed to the gateway.

I resolved the issue disabling any desktop policy on the client; previous modification of the userc file or into the Advanced Settings of the Remote Access of the Global Properties didn't resolve the issue.
Bye.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:48.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0