CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-05
Junior Member
 
Join Date: 2007-09-05
Posts: 3
Rep Power: 0
thomaz has an average reputation (10+)
Default VPN-1 SecuRemote/SecureClient NGX R60 HFA2 problems on Vista & XP

When using the VPN-1 SecuRemote/SecureClient NGX R60 HFA2 on Vista & XP our user are getting their eventlogs flooded (hundreds of messages) with the following error:

Log Name: System
Source: FW1
Date: 03/09/2007 16:55:39
Event ID: 1
Task Category: None
Level: Error
Keywords: Classic
User: N/A
Computer: [xxx]
Description:
FW1: F
Sending reset dire


This problem only occurs when using this SecureClient version, older versions (on XP) are not affected. Any thoughts?
Reply With Quote
  #2 (permalink)  
Old 2007-09-16
Junior Member
 
Join Date: 2007-09-13
Posts: 7
Rep Power: 0
stachr has an average reputation (10+)
Default Re: VPN-1 SecuRemote/SecureClient NGX R60 HFA2 problems on Vista & XP

I've also seen this with SecuRemote NGX R60 HFA-02, but am still at a loss to explain why it occurs!!
Reply With Quote
  #3 (permalink)  
Old 2007-10-20
Junior Member
 
Join Date: 2007-09-05
Posts: 3
Rep Power: 0
thomaz has an average reputation (10+)
Default Re: VPN-1 SecuRemote/SecureClient NGX R60 HFA2 problems on Vista & XP

In the mean time I did some further research on this. It appears that this issue does not occur when I click the "Disable Security Policy" option while connected.

I then tried to disable this option by default, by issuing the "scc sp off" command from a commandline, but then I get "This operation is denied by current settings." Seems that the api_manual_slan_control in my userc.C file is set to false.

Is there another way to disable the security policy by default without having to mess with commandlines or changing the userc.C file?
Reply With Quote
  #4 (permalink)  
Old 2007-11-24
Junior Member
 
Join Date: 2007-09-05
Posts: 3
Rep Power: 0
thomaz has an average reputation (10+)
Default Re: VPN-1 SecuRemote/SecureClient NGX R60 HFA2 problems on Vista & XP

I think I nailed down the issue. After running the SecureClient Log Viewer, Wireshark and the Windows eventviewer side by side, I discovered that the message appears when my client tries to make DNS queries to my provider while connected to the VPN. There is a rule that does not allow this, DNS queries should be routed through the VPN while connected.

A rule is a rule, so I don't have a problem with this. If only my SecureClient would not log an error message in the eventlog each time ;-(
Reply With Quote
  #5 (permalink)  
Old 2007-12-01
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: VPN-1 SecuRemote/SecureClient NGX R60 HFA2 problems on Vista & XP

just set logging in desktop policy for a rule that matches the traffic to no logging

John
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0