CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-22
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default SecureClient-OfficeMode-Routing

R60-HFA03-Splat; Enforcement and Management modules on a single server; we only have one gateway: SecureClient R60 HFA02 also SecureClient R60 client on some laptops. All laptops are running XP SP2, firewall is turned off.
I've just installed the licenses for SecureClient and gotten OfficeMode to work, that is to say it pushes out the ip address and resolves dns. All works well when connected via vpn, whether I'm inside the gateway or outside the gateway.

The problem:
When the client is running but not connected I cannot ping by name or ip address when connected to our internal network. Initially I thought it was a dns problem because I could not ping by name, now I've discovered I can't ping by ip address either, so it's got be routing. I'm not running in Hub Mode. All works well when the client is stopped. My setup worked when using SecureRemote. Everything was configured using the Smart Dashboard, I've not manually edited any files on the gateway or the clients.

Any quick fixes for this problem? If you need additional info let me know.

Other details:
I don't see a difference in the routing tables when the client is running or stopped on the laptops. I'm going through the threads and I see a lot of messages regarding SC and routing.
Reply With Quote
  #2 (permalink)  
Old 2008-01-23
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 159
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

I could be barking up the wrong tree but have you tried this when you have disabling the local security policy on the client.

Right click Secure Client select Tools> Disable Security Policy.

Then try again....I apologizes if you have already done this.


Cheers

Dan
Reply With Quote
  #3 (permalink)  
Old 2008-01-23
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

You need to ensure that your Desktop Policy allows you to connect to the internal network with an unencrypted connection. At the moment your desktop policy won't.

There is an option in the Secure Client Packaging Tool for

Allow clear connections for Encrypt Action when inside the Encryption Domain.

You need to enable this so that your Encrypt Action on your desktop policy will accept an unencrypted connection when you are inside the encryption domain.
Reply With Quote
  #4 (permalink)  
Old 2008-01-23
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Is the Secure Client packaging tool different from running the .msi file? I just ran the .msi file. I have a global property setting, Remote Access | VPN - Advanced | SR/SC behavior while disconnected:
When disconnected, traffic to the encryption domain will be 'Sent in clear'.

How can I enable the option to 'Allow clear connections for Encrypt Action when inside the Encryption Domain'?
Reply With Quote
  #5 (permalink)  
Old 2008-01-23
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Regarding enabling that option. Aren't you just editing some lines in the userc.c file? If so, do you know what lines?
Reply With Quote
  #6 (permalink)  
Old 2008-01-23
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Thanks to both of you for replying. I think I have it solved, or at least SecureClient is working the way we need it too at the moment.
I edited a line in the userc.c file. "allow_clear_in_enc_domain" the default value is false. I changed it to true. This seems to have done the trick.

I do have a question about the Secure Client packaging tool. Will it work with an .msi file?
I couldn't get it to work with one. I noticed that it says to choose an installation folder where the client install files have been upzipped. And, I was also prompted to provide the userc.c file off of the original install cd's.
I didn't have a problem creating the package or installing it. But, when I rebooted the laptop after the install. I got a message popup that said "SecureClient failed to start due to an internal error". I tried using a couple of SecureClient .msi files and different laptops with the same result.
Would someone clue me in?
Reply With Quote
  #7 (permalink)  
Old 2008-01-24
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 276
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Quote:
Originally Posted by Spacetrucker View Post
I do have a question about the Secure Client packaging tool. Will it work with an .msi file?
I couldn't get it to work with one.
----
Would someone clue me in?
Click here...
__________________
There's no place like 127.0.0.1
Reply With Quote
  #8 (permalink)  
Old 2008-01-24
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Many thanks Lammbo, I'm most grateful for such a detailed post from you and the comments of the other forum members. I'll give it a go and see what shakes out. I'm sure to be back with another question.
Reply With Quote
  #9 (permalink)  
Old 2008-01-24
Spacetrucker Spacetrucker is offline
Member
 
Join Date: 2007-03-08
Posts: 74
Rep Power: 2
Spacetrucker has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

I ran into a hitch, I was able to create the base.msi file, and the "allow_clear_in_enc_domain" is set to true. But, Office Mode is not working and the option is grayed out when I checked the client. I need Office Mode. Can you help me out?
Reply With Quote
  #10 (permalink)  
Old 2008-01-25
ldgunnink ldgunnink is offline
Junior Member
 
Join Date: 2006-05-26
Location: Wisconsin, USA
Posts: 17
Rep Power: 0
ldgunnink has an average reputation (10+)
Default Re: SecureClient-OfficeMode-Routing

Quote:
Originally Posted by Spacetrucker View Post
I ran into a hitch, I was able to create the base.msi file, and the "allow_clear_in_enc_domain" is set to true. But, Office Mode is not working and the option is grayed out when I checked the client. I need Office Mode. Can you help me out?
Spacetrucker,

Do you have SecureClient or SecuRemote installed? I have seen this behavior (office mode option grayed out) when SecuRemote is installed.

Loren
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:24.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0