CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-19
Junior Member
 
Join Date: 2006-11-30
Posts: 12
Rep Power: 0
ppayne has an average reputation (10+)
Default Communication with remote VPNs using SecureClient

We have two SPLAT boxes running R65 in a cluster. We have two VPN tunnels to different sites. We have remote users that connect to our network using Secureclient. My question is, is it possible for the Secureclient users to communicate with nodes on our remote VPN sites? Is so, how?
Reply With Quote
  #2 (permalink)  
Old 2007-12-19
Junior Member
 
Join Date: 2007-01-26
Posts: 19
Rep Power: 0
mikem has an average reputation (10+)
Default Re: Communication with remote VPNs using SecureClient

I would think so if you are using hub mode and your network routes correctly.

There could be some NAT issues depending on topology.

Mike
Reply With Quote
  #3 (permalink)  
Old 2007-12-19
Junior Member
 
Join Date: 2006-11-30
Posts: 12
Rep Power: 0
ppayne has an average reputation (10+)
Default Re: Communication with remote VPNs using SecureClient

Thanks for the reply mikem. I have a Star community with "To center and to other satellites through the center" selected. Do i need to do any additional routing in SPLAT?
Reply With Quote
  #4 (permalink)  
Old 2007-12-19
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 291
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Communication with remote VPNs using SecureClient

Since you say you are running SecureClient, I assume you are using Office mode. Since Office Mode subnets are part of your topology, you shouldn't have to do anything else for routing.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 2007-12-20
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Communication with remote VPNs using SecureClient

What I would do is this

Configure your site-to site VPN as normal with normal encryption domains.
Then add the Office mode subnet to the encryption domain of the central gateway.

Your central gateway thus has VPN's to remote gateways and they see the Secure Client Office Mode as being connected to the Central Gateway.

Then on the Central Gateway set a seperate Remote Access Encryption Domain and set this to be the internal nets at the central office and the remote networks behind the remote gateways. Do not include the Office mode in the Remote Access Enc Domain.

This therefore tells the SecureClient that the remote networks are reached by the Central office and the remote gateways know the office mode is reached via the central gateway.

This is how I configure and it works for me on R65.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:22.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0