CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-29
Senior Member
 
Join Date: 2006-11-23
Posts: 159
Rep Power: 3
antonyso88 has an average reputation (10+)
Default netscreen support checkpoint secureclient 4.1

I have a user running secureclient 4.1 (very old version :{ ) through our netscreen 5.0.0 version. After i upgrade the netscreen to 5.3.0, the connection is failed.

Do anyone has my similar experience?
Reply With Quote
  #2 (permalink)  
Old 2007-10-30
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: netscreen support checkpoint secureclient 4.1

Hi
Well I have discussed your problem with my Netscreen friends but they havn't faced any such issue.
Make sure that Ports 500 and 4500 are open at the Firewall.
Let me know what do you see in the smartview logs.Do you get any logs or not?Also check the Netscreen logs also.

Please let me know we will troubleshoot the issue.

Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-10-30
Senior Member
 
Join Date: 2006-11-23
Posts: 159
Rep Power: 3
antonyso88 has an average reputation (10+)
Default Re: netscreen support checkpoint secureclient 4.1

I can't check the smartview side as it is another company. I just can see the netscreen log. But unfortunately, i can't see any log in the netscreen. In addition, i also set the service the "ANY" but still failed.

I am thinking this version is not compatiable with netscreen 5.3 version.

Below is a bug i found in checkpoint secureclient 4.1

UDP encapsulated packets do not reach the destination

Solution ID: skI4512
Creation Date: 09/09/2001
Revised Date: 04/18/2002

Environment: FireWall-1 4.1 SP4, VPN-1 4.1 SP4, SecuRemote 4.1 SP4, UDP Encapsulation, Cisco PIX, Intrusion detection

Symptoms:
UDP encapsulated packets do not reach the destinationUDP Encapsulated packets report about incorrect packet sizeUDP encapsulated packets are dropped by Cisco PIX with intrusion detection software installed

Cause:
In UDP encapsulated packet, the total packet length does not match the actual packet size. The UDP header does not include the 8 bytes for the header size. In the header, the number of bytes of data is used as the "length" of the UDP packet. If the 20 bytes of the IP header are added, the overall length of the packet is 8 bytes shorter than the length reported in the IP field "Total length". This appears to be a problem only if there is an intrusion detection device monitoring the network.

Solution:
Solution is yet not available. Currently under investigation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:50.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0