CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-20
Junior Member
 
Join Date: 2007-11-09
Posts: 5
Rep Power: 0
Pacofe has an average reputation (10+)
Default To mark or unmark automatically SecuRemote

Hi there,

we have some users that usually work inside our net but sometimes need to work outside from our intranet. In both cases they work through the ethernet adapter

When they are in the intranet, they have the Check Point SecuRemote unmarked on the TCP/IP properties in order to not encrypt the comunications.
When they are outside our intranet, they have the Check Point SecuRemote marked on the TCP/IP properties in order to establish a VPN with our site.

Our users are not administrators users, therefore they can't change TCP/IP's properties.

Is there someway of do it automatically by a command or script?

Thanks!

Best regards.
Reply With Quote
  #2 (permalink)  
Old 2007-11-24
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 151
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: To mark or unmark automatically SecuRemote

Normaly there is no need to change tcp/ip settings at the client site.

At the client do the following steps.
- stop SecureClient/Remote
- make shure SecueClient/Remote is enabled at the Ethernet adapter (tcp/ip) settings.
- set the following parameter in the file userc.C to true
:allow_clear_in_enc_domain (true)

Check this parameter again after a successfull connect to the vpn gateway!

With newer version of CP you have this option in SmartDashboard

[Policy] -> [Global Properties] -> (Remote Access) -> (VPN Advanced)
When disconnected traffic to the encrypion domain will be
[ ] Dropped
[X] Send in clear
If this is not working for you give a little more detail.
CP Version, SecureClient/Remote version maybe OS
Reply With Quote
  #3 (permalink)  
Old 2007-12-04
Junior Member
 
Join Date: 2007-11-09
Posts: 5
Rep Power: 0
Pacofe has an average reputation (10+)
Default Re: To mark or unmark automatically SecuRemote

Thanks dsb.nepo,

I think this is the solution we was looking for.

I've test it and it works properly although I think I have some problems with the Desktop Rules.

Thanks!
Reply With Quote
  #4 (permalink)  
Old 2007-12-04
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 151
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: To mark or unmark automatically SecuRemote

for the desktop rules keep in mind
- All Users@ -> rules apply if the client is disconnected
- DefinedUserGroup@ -> rules apply if the client is connected

You can verify this if you open the CheckPoint diagnose at the client side
from the 'windows program menu' and watch the applied rules.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:44.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0