CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-21
Junior Member
 
Join Date: 2007-06-16
Posts: 6
Rep Power: 0
aberka has an average reputation (10+)
Default Connected, but interface doesn't start (VISTA)

I have NGX R60 HFA2 and under Vista, although username is verified and VPN client reports CONNECTED, the interface is started and no route is added. Tray icon looks like connected.

This is a part from ipconfig /all before connection:

Code:
Adapt‚r sˇtŘ Ethernet Pýipojenˇ k mˇstnˇ sˇti* 10:

   Stav m‚dia  . . . . . . . . . . . : odpojeno == THIS MEANS DISCONNECTED
   Pýˇpona DNS podle pýipojenˇ . . . : 
   Popis . . . . . . . . . . . . . . : Check Point Virtual Network Adapter For SecureClient
   Fyzick  Adresa. . . . . . . . . . : 54-F7-C8-68-FF-12
   Protokol DHCP povolen . . . . . . : Ano
   Automatick  konfigurace povolena  : Ano
and after successfull login:

Code:
Adapt‚r sˇtŘ Ethernet Pýipojenˇ k mˇstnˇ sˇti* 10:

   Stav m‚dia  . . . . . . . . . . . : odpojeno
   Pýˇpona DNS podle pýipojenˇ . . . : 
   Popis . . . . . . . . . . . . . . : Check Point Virtual Network Adapter For SecureClient
   Fyzick  Adresa. . . . . . . . . . : 54-F7-C8-68-FF-12
   Protokol DHCP povolen . . . . . . : Ano
   Automatick  konfigurace povolena  : Ano
= the same thing.

I tried to disable user account security something in Vista.

Connections status looks like:

Code:
Checking network connectivity...
Preparing connection...
Connecting to gateway...
User AB14CZEX authenticated by Radius authentication 
Connected to gateway
Detecting network parameters...
Connection succeeded
Any ideas? This complicates my life a LOT :(

Thanks for any help.
Reply With Quote
  #2 (permalink)  
Old 2007-06-22
Senior Member
 
Join Date: 2006-01-25
Posts: 917
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Did you violate any of these known limitations?

Quote:
1) SecureClient for 64Bit Windows is not supported.


2) Upgrading from Windows XP or Windows 2000 to Windows Vista while SecureClient
is installed is currently not supported. Workaround:
1 Uninstall SecureClient.
2 Upgrade operating system.
3 Install SecureClient NGX HFA_02.


5) Despite new elevation capabilities of User Account Control in Windows Vista, SecureClient NGX HFA_02 can only be installed by an administrator or a member of the Administrators group.
Otherwise turn on SecureClient logging and examine the output of the connection log.

Last edited by melipla; 2007-06-22 at 07:57.
Reply With Quote
  #3 (permalink)  
Old 2007-06-26
Junior Member
 
Join Date: 2007-06-16
Posts: 6
Rep Power: 0
aberka has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Thanks for replying!

>Did you violate any of these known limitations?
>Quote:
>1) SecureClient for 64Bit Windows is not supported.
Windows Vista 32b Bussiness Czech
>2) Upgrading from Windows XP or Windows 2000 to Windows Vista while >SecureClient
>is installed is currently not supported. Workaround:
>1 Uninstall SecureClient.
>2 Upgrade operating system.
>3 Install SecureClient NGX HFA_02.
I had a clean installation of Vista

>5) Despite new elevation capabilities of User Account Control in Windows >Vista, SecureClient NGX HFA_02 can only be installed by an administrator or >a member of the Administrators group.
>Otherwise turn on SecureClient logging and examine the output of the >connection log.
I have turned the UAC off. I'm the only user on that machine, I'm a member of Admin group.

I don't see anything suspicious in the logs: http://aleq.xf.cz/fw/SC_logs_26_Jun_07_18_46_20.tgz and http://aleq.xf.cz/fw/SC_logs_26_Jun_07_18_51_23.tgz

Thanks for help.
Reply With Quote
  #4 (permalink)  
Old 2007-07-16
Junior Member
 
Join Date: 2006-10-24
Posts: 6
Rep Power: 0
giallorossi77 has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Hi,
I have to same problem, SNX connected but no routes imported.

Any suggestione?

Luciano
Reply With Quote
  #5 (permalink)  
Old 2007-07-16
Junior Member
 
Join Date: 2007-06-16
Posts: 6
Rep Power: 0
aberka has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

No solution. It simply doesn't work under Vista for me. I'm using VMware with XP and tunnels between Host and VMware. Terrible.
Reply With Quote
  #6 (permalink)  
Old 2007-07-18
Junior Member
 
Join Date: 2006-10-24
Posts: 6
Rep Power: 0
giallorossi77 has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Hi guys,
I tried again using a R65 Standalone installation. The SNX client was installed correctly (no need to work on UAC) but still no routes added to the routing table of the Vista PC.

Still wondering if it will ever work......
Reply With Quote
  #7 (permalink)  
Old 2007-07-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

When you say routes added to the routing table, you don't see routes added, you just the virtual network adapter with it's IP settings and Default Gateway etc when connected or without an IP if not connected.

Does it work on Xp for you as all I get is the virtual network adaptor and then the Office Mode settings appear in there when connected. I don't ever get routes added to my routing table.
Reply With Quote
  #8 (permalink)  
Old 2007-07-19
Junior Member
 
Join Date: 2007-06-16
Posts: 6
Rep Power: 0
aberka has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Am I the only one who doesn't understand the previous post? :-)
Reply With Quote
  #9 (permalink)  
Old 2007-07-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

What I was saying was why are you expecting to see routes added to the routing table with SecureClient.

Asked if it worked under XP for him.

Hardly rocket science.
Reply With Quote
  #10 (permalink)  
Old 2007-07-23
Junior Member
 
Join Date: 2006-10-24
Posts: 6
Rep Power: 0
giallorossi77 has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Hi, we are talking about SNX and how the vista client knows about the encryption domain when it get connected to the firewall.

Routes are added to the host routing table in order to get it reach the encryption domain exported by the firewall.
This is what my xppro pc get when it connects to a vpn-1 using the SNX:

10.1.1.1 255.255.255.255 192.168.253.250 192.168.253.251 1
10.1.1.8 255.255.255.255 192.168.253.250 192.168.253.251 1
10.1.1.10 255.255.255.255 192.168.253.250 192.168.253.251 1
10.1.4.3 255.255.255.255 192.168.253.250 192.168.253.251 1
10.5.2.1 255.255.255.255 192.168.253.250 192.168.253.251 1
10.6.1.2 255.255.255.255 192.168.253.250 192.168.253.251 1
10.6.3.206 255.255.255.255 192.168.253.250 192.168.253.251 1
10.13.1.1 255.255.255.255 192.168.253.250 192.168.253.251 1
10.16.1.1 255.255.255.255 192.168.253.250 192.168.253.251 1
10.19.1.4 255.255.255.255 192.168.253.250 192.168.253.251 1
10.19.1.6 255.255.255.255 192.168.253.250 192.168.253.251 1

where 192.168.253.251 is the ip address of the "Check Point Virtual Network Adapter For SSL Network Entexder"

Hope this help.

Luciano
Reply With Quote
  #11 (permalink)  
Old 2007-07-23
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Connected, but interface doesn't start (VISTA)

Apologies for the confusion, I assumed it was SecureClient that you was on about as this is the SecureClient area, and the original thread start was about SecureClient on Vista.

There is a seperate area for SNX issues which is why assumed was SecureClient
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 15:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0