CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-31
Member
 
Join Date: 2007-08-30
Posts: 34
Rep Power: 0
venkatnarayana has an average reputation (10+)
Default not able to access particular subnet devices

Hi all

when my secureclient users connect to the site they are not able to access a particular subnet devices, where as they are able to connect to other subnet devices.

i have created a rule specifically for the subnet by allowing it but still the users are not able to connect.

regards
Reply With Quote
  #2 (permalink)  
Old 2007-10-31
Senior Member
 
Join Date: 2006-01-25
Posts: 914
Rep Power: 3
melipla has an average reputation (10+)
Default Re: not able to access particular subnet devices

Where does a traceroute go? Is the network in your VPN domain? Is the client's LAN network overlapping with your VPN domain?
Reply With Quote
  #3 (permalink)  
Old 2007-11-14
Member
 
Join Date: 2007-08-30
Posts: 34
Rep Power: 0
venkatnarayana has an average reputation (10+)
Default Re: not able to access particular subnet devices

yes the network in our vpn domain but at a remote site. the clients lan network in not overlapping.

this is a site to site vpn. we are able to access between site to site , but the secureclient users are not able to access only servers on a particular subnet.
Reply With Quote
  #4 (permalink)  
Old 2007-11-14
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: not able to access particular subnet devices

Quote:
Originally Posted by venkatnarayana View Post
yes the network in our vpn domain but at a remote site. the clients lan network in not overlapping.

this is a site to site vpn. we are able to access between site to site , but the secureclient users are not able to access only servers on a particular subnet.

Either:

a) Use route all traffic on the secureclient
or
b) define remote subnets in your gateway objects->topology "set domain for remote access comunity)

and ofc have rules in the rulebase allowing this kind of traffic.


If you are gonna try with route all traffic, besided changing the setting on the client (or profile depending on your setup) dont forget to activate "allow secureclient to route traffic through this gateway" option. It can be found on gateway object->remote access tab
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:25.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0