CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-22
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default SecureClient working with NGX

Hi, I'm after help with a problem of SecureClient working to firewalls installed with NGX. Remote users were working ok to NG_AI but failed once the firewalls were upgraded to NGX. When reverted back to NG_AI access ok again.
Subsequent testing implied that the problem was with the IKE Phase1 key exchange (default using UDP 500). The SecureClient diagnostics showed the failure, with an error 108.
Also we found that the problem only occued if the firewall was a member of a cluster object. If used as a single firewall object it worked ok. It also worked as a cluster member if IKE over TCP was used. The NGX fix has been applied to both the management server and firewall.
Checkpoint is running on Nokia's using ipso 3.9
Reply With Quote
  #2 (permalink)  
Old 2005-12-22
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient working with NGX

What version of SC are you using?

Are you using IPSO cluster or ClusterXL?

What "mode" (Unicast/pivot or Multicast/New-mode)?

Try it with pivot mode if you're not using that. Multicast mode still has problems with some switch/routers that are not fully RFC complient with the multicast specs.

-jlh
Reply With Quote
  #3 (permalink)  
Old 2005-12-23
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default Re: SecureClient working with NGX

Jim

Thanks for the reply. The SC being used is R56. We're not using either IPSO clustering or ClusterXL. The firewall's (Nokia IP530 hardware) are setup in a simple failover pair using monitored cct. This works fine in NG_AI.

david
Reply With Quote
  #4 (permalink)  
Old 2005-12-23
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient working with NGX

Making sure I under stand....

R60 VPN-1 on IPSO 3.9 w/ VRRP HA

R56 SC/SR

Works with TCP encapcilation but fails with just UDP encap.
========

Did you try the R60 SC/SR? I can't find any refference to that error but I don't have access to the Nokia KB.
Reply With Quote
  #5 (permalink)  
Old 2006-01-04
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default Re: SecureClient working with NGX

Jim, Firewalls are IP530 running IPSO 3.9. They are set up as a HA pair using vrrp monitored cct. When using NG_AI vpn access using SecurClient works fine. Upgrading to NGX access fails, not even able to create site, using default of UDP IKE. If IKE over TCP is used site creates ok. No difference whether SC R56 or R60 used.
In a test enviroment with a single firewall at NGX vpn access ok. If that firewall is made a member of a cluster access fails.
Reply With Quote
  #6 (permalink)  
Old 2006-01-04
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient working with NGX

Using IKE over TCP does everything keep working after the site is created?

I seem to remember something about IKE UDP and cluster problems, but I don't remember it being an R60 issue. I'll take another look through the KB.

-jlh
Reply With Quote
  #7 (permalink)  
Old 2006-01-06
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default Re: SecureClient working with NGX

Jim, using IKE over TCP the site is created and then you are able to login ok
Reply With Quote
  #8 (permalink)  
Old 2006-01-06
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: SecureClient working with NGX

Quote:
Originally Posted by djbutler
Jim, using IKE over TCP the site is created and then you are able to login ok
Are the users stored locally or on LDAP server?
Reply With Quote
  #9 (permalink)  
Old 2006-01-10
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default Re: SecureClient working with NGX

Quote:
Originally Posted by Sergej
Are the users stored locally or on LDAP server?

Users are stored locally
Reply With Quote
  #10 (permalink)  
Old 2006-01-10
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient working with NGX

Quote:
Originally Posted by djbutler
Jim, using IKE over TCP the site is created and then you are able to login ok
I can't find the KB number, but this is one of the things IKE over TCP is meant to take care of.

If it works with IKE/TCP, is using that an issue?

-jlh
Reply With Quote
  #11 (permalink)  
Old 2006-01-13
Junior Member
 
Join Date: 2005-12-22
Posts: 7
Rep Power: 0
djbutler has an average reputation (10+)
Default Re: SecureClient working with NGX

Quote:
Originally Posted by chillyjim
I can't find the KB number, but this is one of the things IKE over TCP is meant to take care of.

If it works with IKE/TCP, is using that an issue?

-jlh
Jim, At present remote users are working fine through NG_AI firewalls and to be honest I don't want them making changes to settings.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0