CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-16
rubber_chicken rubber_chicken is offline
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 92
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default SecureClient routing stops after changing from IPSO to SPLAT

Hi all,

Apologies if I’ve miss-posted this. I suspect this a version difference, although it could be a routing issue or a SecureClient issue.

I’ve got a legacy system (six R55 boxes running on Nokia) with an R61 Management box running on Win 2003. To allow users to VPN into one main site and connect through there to other sites we use the vpn_route.conf config file.

Last week, the hard drive died in one of the main Nokia boxes. I built an R61 SPLAT box to replace it. All is back up and working well except the SecureClient routing. I can see the traffic being encrypted, but I’m not getting a connection.

Consider the following simplified setup



GW1 is a Nokia running R55. Internal anti-spoofing is 10.1.0.0/16
GW2 is a SPLAT running R61. Internal anti-spoofing is 10.2.0.0/16
Office mode pool for GW1 is 10.1.254.0/24
Office mode pool for GW2 is 10.2.254.0/24

If I connect using SecureClient via GW1 I can get to all networks
If I connect using SecureClient via GW2 I can only get to LAN2, 1, 3 & 5.

I’ve confirmed that the routes are correct on the new GW2 as I have full connectivity via the site to site VPN. I’ve also confirmed the return route on the router on LAN2 (sorry not drawn) returns traffic for the Office mode pool 10.2.254.0 back to GW2

Hence, I suspect that there is an option that I have not turned on in SPLAT to enable this.

No routes have been changed (other than being redone on the new GW2) and until the unit died, it was working fine.

Any ideas?
Reply With Quote
  #2 (permalink)  
Old 2008-01-02
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 839
Rep Power: 3
melipla has an average reputation (10+)
Default Re: SecureClient routing stops after changing from IPSO to SPLAT

From your drawing it appears that LAN4 and LAN6 are routed through LAN2?

Since 4 & 6 aren't working for SecureClient sourced IPs but are working for LAN1/3/5/2 sources then that indicates a problem with routing for these two networks w/secureclient addresses. Since GW 2's OM IPs can access LAN2, then the disconnect in routing must be the return path for LAN4/6 to GW 2's OM IPs.
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2008-01-29
rubber_chicken rubber_chicken is offline
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 92
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default Re: SecureClient routing stops after changing from IPSO to SPLAT

Hi,

Apologies for the delay in getting back to you. A long Xmas/New Years break (it's a glorious summer here in NZ) made me forget all about work. I resolved this, and yes it was a routing issue made by my own haste.

In my rush to rebuild the broken system, I had added a route for the Office Mode pool on GW2 that caused a routing loop between it and the core router in LAN2.

As soon as I removed this offending route all started working perfectly again.

Thanks very much for your time to reply, it made me go through and justify all my static routes. It is greatly appreciated.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:51.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0