CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-12
Junior Member
 
Join Date: 2005-10-12
Posts: 6
Rep Power: 0
jcamillo has an average reputation (10+)
Default Office Mode and ipassignment.conf

I have a problem with using office mode. I would like my users to get different IP information. For example I want some users to only get an IP and not DNS and some users to get an IP address and DNS.

I have been trying to use the file ipassignment.conf located on fw mod $FWDIR/conf directory. I have been editing the file with VI and when I run the verifier it checks and there are no errors. when I logon to SC I dont recieve the IP address I specified in the IPassignment file.

I have tried different formats and also rebooting, cprestarting, pushing policy and still no luck.

I also checked om_prevent_ippool_nat_for_users in objects C to true.

I am currently running on my mangement R60 on win 2003 and FW module is running R55 on Nokia 3.8
Reply With Quote
  #2 (permalink)  
Old 2005-10-12
Junior Member
 
Join Date: 2005-10-12
Location: Germany
Posts: 7
Rep Power: 0
simon has an average reputation (10+)
Send a message via Skype™ to simon
Default Re: Office Mode and ipassignment.conf

Hi jcamillo,

make sure you define more specific entries on top of your generic settings.

For example:
Line #1: cpmodule addr 192.168.1.100 wins=(), dns=() JohnDoe
Line #2: cpmodule net 192.168.1.0/27 wins=(192.168.1.200), dns=(192.168.1.200) VpnUserGroup


JohnDoe may be a member of VpnUserGroup or not, in this case it doesn't matter because the more specific entry is specified above the generic entry. If JohnDoe ist not a member of VpnUserGroup you could also specify it below.
If no entry matches (no membership in VpnUserGroup, not user JohnDoe) the module's object configuration defined on your SmartCenter Server should match.

You can also use vpn ipafile_check ipassignment.conf detail for more detailed output.

Hope that helps.

Regards,
Simon
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 15:53.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0