CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-11
Junior Member
 
Join Date: 2006-12-14
Posts: 19
Rep Power: 0
prdehoop has an average reputation (10+)
Default Wrong officemode adress after changing the office pool

Hi,

I have an test situation for taking in production. i expiriense a problem whem i change the officemode pool to an new pool. The old clients still use there old ip adres from the old office pool with it not used anymore.

Is there a way to flush the dhcp table so everybody that logs in get the an new ip of the new pool ?

Regards

Checkpoint NGX R60
Secure client R56 and R60
Reply With Quote
  #2 (permalink)  
Old 2007-12-11
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

Unfortunately I've experienced the same thing. I'm not sure if these clients reconnect before the lease time expires enabling them to renew it but there is definitely odd behavior with OM IPs leases.

The easiest way I've found to reset their OM is to remove it. SecureClient records the OM IP it receives into the systems registry. Removing the registry entry will force SecureClient to retrieve a new OM IP.

HKLM\Software\CheckPoint\SecuRemote\5.0\OM

You should see a "OM.<gateway IP>" which has the value of their current OM IP.

HTH
Reply With Quote
  #3 (permalink)  
Old 2007-12-15
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

I know with R55 you had to reboot the firewall for a change in the Office Mode IP Pool to take effect. There is an SK article about it. I don't know if this needs to be done for NGX, though.

Ray
Reply With Quote
  #4 (permalink)  
Old 2007-12-15
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

The issue is still there in NGX. NGX will cache an association between the username and allocated OM IP address for the lease time. cpstop/cpstart will normally fix it IIRC.
Reply With Quote
  #5 (permalink)  
Old 2007-12-18
Junior Member
 
Join Date: 2006-12-14
Posts: 19
Rep Power: 0
prdehoop has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

thanxs all, the only fix we found was cpstop cpstart as mentioned above.

Its a strange bug that isn't fix still not in R60, still need to check R65 if its fixed there, i'm afraid that we need an restart there also..

Keep you'll informed.
Reply With Quote
  #6 (permalink)  
Old 2007-12-18
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

It's not a bug, it's by design - the lease is reserved for continuity if the SR/SC connection drops out.
Reply With Quote
  #7 (permalink)  
Old 2007-12-26
Junior Member
 
Join Date: 2007-02-25
Posts: 2
Rep Power: 0
scottikon has an average reputation (10+)
Default Re: Wrong officemode adress after changing the office pool

Securknowledge article sk30550 is worth a read. It does mention about manually clearing the OM connections table on the gateway: -

"* fw tab -t marcipan_ippool_users -x command - used to manually clear the Office Mode connections table on the Gateway; this can be used after making changes to the Office Mode IP addresses, instead of rebooting the Gateway to make those changes effective."
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0