CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-05
Junior Member
 
Join Date: 2007-03-12
Posts: 15
Rep Power: 0
elzilcho has an average reputation (10+)
Default Default gateway on route all traffic through tunnel

Hopefully someone will know for sure, but need some confirmation to a suspicion I have...

When customer uses secure client and doesn't tick the "route all traffic through tunnel" option, he doesn't get a default gateway assigned.

When he does tick this option he is assigned a default gateway- which is always the first IP in the range of addresses from the pool.

eg. 192.168.1.0 /24 is the range, he gets 192.168.1.20 with a DG of 192.168.1.1

Is this a built-in feature of the firewall that it will allocate the first address in the range as the DG when "tunnel all" is ticked? As I can't see anything configurable within the policy to this effect. Also, if this is the case, I imagine the firewall is intelligent enough to know not to assign the .1 address as the user's IP?
Reply With Quote
  #2 (permalink)  
Old 2007-12-05
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Default gateway on route all traffic through tunnel

Quote:
Originally Posted by elzilcho View Post
Is this a built-in feature of the firewall that it will allocate the first address in the range as the DG when "tunnel all" is ticked? As I can't see anything configurable within the policy to this effect. Also, if this is the case, I imagine the firewall is intelligent enough to know not to assign the .1 address as the user's IP?
The "route all traffic through the tunnel" is also known as "Hub Mode". I've found that the default gateway IP may change, but will always be an IP from the OM pool. The .1 default route basically says to route all traffic to the firewall--it doesn't impact how the firewall routes it. So it doesn't matter if the .1 address is used by another client because when the firewall receives the encrypted packet, it will decrypt it and route it accordingly.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 15:07.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0