CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-22
anakalem anakalem is offline
Junior Member
 
Join Date: 2008-01-13
Posts: 28
Rep Power: 0
anakalem has an average reputation (10+)
Default SecureClient disconnected when site2site vpn tunnel up

Hi all,

i have problem and i need your expertise.
I have configured remote access vpn and site to site vpn. Both work if activate it one at a time.
The problem is actually with remote access, when i remote the the firewall and then i bring up the tunnel of that firewall to other firewall (site2site), my secureclient got disconnected. Here the diagram :

HostA (me)---->FWA=====FWB

FWA have site2site vpn with FWB, while iam still using the remote. The one who disconnect is FWA.
The error said No valid SA in the tracker. The community of course is different.

Can both type VPN active in one firewall? if yes, what's the catch?

Please advise

Thank you

Cheers
Kalem
Reply With Quote
  #2 (permalink)  
Old 2008-01-22
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 461
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: SecureClient disconnected when site2site vpn tunnel up

The problem is that your SR connection is NATted behind the FireWall's IP address. THe firewall is configured to expect a site-site VPN connection from that IP, not a Remote Access VPN connection. You can resolve this by using a different IP address to Hide-NAT outbound connections, just ensure that this address is outside the encryption domains.
Reply With Quote
  #3 (permalink)  
Old 2008-01-23
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: SecureClient disconnected when site2site vpn tunnel up

Or do this

enable the send_clear_traffic_between_encryption_domains property in objects_5_0.C. on the SMARTCenter and then install a policy to the gateways.

You cannot run a Remote Access VPN connectivity when sat inside the encryption domain of another gatewat that has a site-site VPN connection.

This is the recomended Check Point solution from the VPN Admin Guide.

If you have a site to site tunnel then whey need to build a Remote Access as well.

This requires that FWA and FWB are managed from the same SMARTCenter and only works if you have one active site defined on your Remote Access Client.
Reply With Quote
  #4 (permalink)  
Old 2008-01-24
anakalem anakalem is offline
Junior Member
 
Join Date: 2008-01-13
Posts: 28
Rep Power: 0
anakalem has an average reputation (10+)
Default Re: SecureClient disconnected when site2site vpn tunnel up

Quote:
Originally Posted by mcnallym View Post
This requires that FWA and FWB are managed from the same SMARTCenter and only works if you have one active site defined on your Remote Access Client.
Guys big thank you for your solutions. However, solution from thorpuse i dont think it may work in my case, since we only have 1 ip range for public / external interfaces, the rest, is the private ip.

solution from mcnallym, this two firewall, basically not managed by the same smartcenter, since the othe rone is different vendor managed it. Probably can't do as well.

Maybe i must enforce them to use site to site rather than remote access.
Thank you guys... if there is any solution, i'll be very grateful

regards
Kalem
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:15.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0