CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-17
justin.knox justin.knox is offline
Junior Member
 
Join Date: 2005-09-30
Posts: 23
Rep Power: 0
justin.knox has an average reputation (10+)
Default RemoteAccess Configuration issues -- NGX/R60_HFA01.

Hi. I'm a relative newb to Check Point, the last time I did any work with it was pre-4.1. Here's my issue:

I'm in the process of a pilot roll-out of Check Point Express NGX. I'm doing this as a distributed deployment, management server is running as a virtual machine in VMware: Windows Server 2003, SP1. The enforcement module is an IP260 appliance from Nokia, running IPSO 3.9 Build 041.

I've installed R60 via the wrapper .tgz on the appliance, and I've had no trouble establishing SIC and managing my rulebase, in fact I've got that all working fine. However, I've added a rule to permit RemoteAccess users in. I've got a test user configured for preshared secret _and_ certificate, and when I use SecuRemote to attempt connection to the gateway from the internet segment of the pilot, I get an error in SmartView Tracker indicating the enforcement point has no key for IKE (phase 1 I'm betting here). The SecuRemote client also gets told that the gateway has no certificate for IKE and cannot connect (can't even complete creation of the site).

SmartView Tracker does show a successful, permitted Topology request just before this error, so I am sure there's no connectivity issues here. I've got a ticket opened with support, and we've gotten this far (before I was receiving an error stating that the user was not correctly configured).

Am I missing something? Is there anything that needs to be done via Voyager or CLISH that SmartCenter does not handle?
I've already got a request to purchase most of the recent books recommended by the group. I've also got a budget request for training, unfortunately my deadline is closer than both of those dates.

any help is appreciated
Reply With Quote
  #2 (permalink)  
Old 2005-10-17
justin.knox justin.knox is offline
Junior Member
 
Join Date: 2005-09-30
Posts: 23
Rep Power: 0
justin.knox has an average reputation (10+)
Default Re: RemoteAccess Configuration issues -- NGX/R60_HFA01.

I solved my own problem:
prior to applying HFA 01, when I clicked on the View button on my firewall object's VPN tab, I got an empty message box. After applying HFA 01, when doing the same I get a message box indicating that the certificate could not be read from the database.
I removed the firewall object from the RemoteAccess VPN community, and unchecked the public key authentication method in the Traditional VPN Configuration options. I then clicked Remove to remove the certificate from the firewall object, confirmed the selection and clicked OK. I then installed my policy to the firewall

Then, I re-opened my firewall object for editing, clicked Create on the VPN tab, and created a new certificate. I clicked OK, and installed the policy.

Finally, I went back into the VPN tab, re-enabled the public key authentication method, and added the firewall back to the remote access community. Clicked OK, installed policy.

I can now connect to my gateway via SecuRemote.
props go to this link:
http://msgs.securepoint.com/cgi-bin/...309/196/1.html
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:56.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0