CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-15
tim@nextmedium tim@nextmedium is offline
Junior Member
 
Join Date: 2007-11-15
Posts: 3
Rep Power: 0
tim@nextmedium has an average reputation (10+)
Default VPN Users in one site can't seen network services in other sites.

Greetings to all -
I've been administering three Checkpoint Edge devices for about a year and only recently discovered CPUG (as recently as today - yay for Google).

Does anyone have experience with the following issue? We're using three Edge devices (2 Edge X devices and one Edge W device) connected site-to-site. Topology is as follows:
[IMG][/IMG]
VPN users in any site (A, B or C) may connect and view network resources in that site. However, they may not view network resources in other sites without enabling "Route All Traffic Through Gateway".

"Route All Traffic..." has been deemed unacceptable since it forces them to browse the Internet through their VPN-tunnel (substantially slower than what they would normally get). I've been asked to find a different way.

Working with Checkpoint support has led us to the "No - only 'Route All Traffic...' will work" answer. Other people have hinted that you can hack the user.c file successfully and use that topology info to see resources in all three sites without "Route All Traffic..." turned on.

Can you hack the User.C file? If so - how to do so successfully? I've already tried incorporating all three sites "topology" entries into one single site - this causes Secureremote NOT to work (services will not start; had to reinstall).

I should also mention that I haven't completely mined CPUG yet for this answer (did usual text searches) - if a FAQ has already been written and I haven't seen it, apologies and would you be kind enough to steer me toward it?

Thanks!

Tim

Last edited by tim@nextmedium; 2007-11-15 at 16:22.
Reply With Quote
  #2 (permalink)  
Old 2007-11-28
tim@nextmedium tim@nextmedium is offline
Junior Member
 
Join Date: 2007-11-15
Posts: 3
Rep Power: 0
tim@nextmedium has an average reputation (10+)
Default Re: VPN Users in one site can't seen network services in other sites.

...bump...
Reply With Quote
  #3 (permalink)  
Old 2007-11-28
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: VPN Users in one site can't seen network services in other sites.

I could do this if you had a full Gateway at one location as you can have a seperate Secure Remote Topology to a Site to Site Topology. It also relies on Secure Client Office Mode to route the traffic back correctly to the first gateway.

If a full gateway then

EdgeA-Enc-Dom = LocalNet
EdgeB-Enc-Dom = LocalNet
VPN1-Site-Enc-Dom = LocalNet+Office Mode net
VPN1-RemoteAccess-EncDom=All 3 local nets.

This way you remote into the Central Site and can access all three sites going across the Site-to-Site VPN's between the Edge and Central.

However I don't think it is possible with just 3 Edge Boxes.
Reply With Quote
  #4 (permalink)  
Old 2007-11-29
tim@nextmedium tim@nextmedium is offline
Junior Member
 
Join Date: 2007-11-15
Posts: 3
Rep Power: 0
tim@nextmedium has an average reputation (10+)
Default Re: VPN Users in one site can't seen network services in other sites.

Thanks for the response - We've come to the same conclusion and are looking at alternatives. Again - thanks so much for responding.
Reply With Quote
  #5 (permalink)  
Old 2007-11-30
JohnMH JohnMH is offline
Member
 
Join Date: 2006-07-15
Posts: 68
Rep Power: 3
JohnMH has an average reputation (10+)
Default Re: VPN Users in one site can't seen network services in other sites.

This isn't hard to do... Here is what we do.

Make sure you have rules in Desktop policy that allow the UserGroup@encDomainA talk to EncDomain B and the reverse.

Then when a client is in one of the encDomains we always have them disable the site. The client is still being protected by the SecureClient firewall and rules in that firewall are still in effect.

Works with us.

John
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:33.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0