CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-23
SuderMan SuderMan is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 13
Rep Power: 0
SuderMan has an average reputation (10+)
Default SecureClient issues

Hello !

I've got 2 questions.

1) Is Checkpoint's SecureClient with Office mode can be used without installed Policy Server on Gateway (NG R55) ?

In my case SecureClient is connecting to Firewall then getting local ip address (Office mode) but then it cannot go anywhere.

I'm not sure it's becouse of misconfiguration or lack of Policy Server installed ?

secureClient Diagnostics is indicating that Machine is not securely Configured - SCV is not verified.

-------------

2) DNS when using SecureClient without office mode or SecuRemote.

In that case SecureClient or SecuRemote client doesn't get local private address and therefore cannot connect to resources using dns names. it's possible only when using ip address. All resorces are within internal network with private addresses.

This is quite obvious ... becouse client is using existing network connection with DNS Servers that cannot resolve our private addresses

but is it possible somehow for clients to use internal DNS Servers without adding them manually to existing network connection ?

Is there a workround for this ?

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2005-12-24
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient issues

1. SecureClient can be used without a policy server but it does still (legally anyway) require a license. The licensing wasn't enforced well before R60.

You need to check your "Remote Access" settings on the gateway and make sure it is set to allow non-verified connections. Also make sure that the office mode pool is routable within your network or is being NATed to something that is.

2. There are some ways to get around this but none are really good. Giving people a host table is one way around it, and probably the safest way.

SecureClient's office mode is the "right" way to do this.

That being said, you should complain to your local Check Point SE/Sales Rep that this should be part of SecuRemote and not a charged item. If enough people complain, TPTB will listen.
Reply With Quote
  #3 (permalink)  
Old 2005-12-27
SuderMan SuderMan is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 13
Rep Power: 0
SuderMan has an average reputation (10+)
Default Re: SecureClient issues

Concerning SecureClient does some port of local ip pool which is assigned for office mode need to be forwarded outside the NAT device ?
Reply With Quote
  #4 (permalink)  
Old 2005-12-29
SuderMan SuderMan is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 13
Rep Power: 0
SuderMan has an average reputation (10+)
Default Re: SecureClient issues

Ok thanks I've already managed to solve the problem ..
Reply With Quote
  #5 (permalink)  
Old 2006-01-09
eric_packer eric_packer is offline
Junior Member
 
Join Date: 2006-01-09
Posts: 1
Rep Power: 0
eric_packer has an average reputation (10+)
Default Re: SecureClient issues

Quote:
Originally Posted by SuderMan
Ok thanks I've already managed to solve the problem ..
Care to share your solution to #2, please? Thanks!
Reply With Quote
  #6 (permalink)  
Old 2006-01-10
SuderMan SuderMan is offline
Junior Member
 
Join Date: 2005-11-28
Posts: 13
Rep Power: 0
SuderMan has an average reputation (10+)
Default Re: SecureClient issues

Here is checkpoint's answer:
Solution ID: #skI2065

Product: SecuRemote
Version: NG
Last Modified: 15-Jul-2004

Solution

To set up Split DNS for VPN-1/FireWall-1 NG and SecuRemote/SecureClient NG, proceed with the following:

Create a Host Node network object in the Policy Editor
1. Select Manage > Network Objects
2. In the Network Objects dialog box, click on New and select Node > Host from the drop down list
3. In the Host Node dialog box, select General Properties in the left pane
4. In the Host Node - General Properties, enter the network object name of the internal DNS server in the Name field (ie. internal_dns)
5. Enter the IP address of the of the internal DNS in the IP Address field (ie. 192.168.2.100)
6. Click on OK in the Host Node dialog box
7. Click on Close in the Network Objects dialog box

Create a SecuRemote DNS server object in the Policy Editor
1. Select Manage > Servers
2. In the Servers dialog box, click on New and select "SecuRemote DNS..." from the drop down list
3. In the SecuRemote DNS Properties dialog box, select the General tab
4. In the General tab, enter the SecuRemote DNS server name for the SecuRemote DNS server in the Name field (ie. sr_dns_server)
5. Select the network object of the internal DNS server (ie. internal_dns) from the Host drop down list
6. In the SecuRemote DNS Properties dialog box, select the Domains tab
7. In the Domains tab, Click on Add
8. In the Domain dialog box, enter the domain suffix of the internal network in the Domain Suffix field (ie. detroit.com)
9. In the Domain Match Case section, select "Match only *.suffix" option

Note:
If internal network workstations have a name such as pcstation.sales.detroit.com (two labels preceding the domain suffix), select "Match up to ** labels preceding the suffix" option rather than the "Match only *.suffix" option. Adjust the number of labels in this option according to the maximum number of labels that may precede the domain suffix.

10. Click on OK in the Domain dialog box
11. Click on OK in the SecuRemote DNS Properties dialog box
12. Click on Close in the Servers dialog box
13. Install the security policy

Note:
After the security policy is installed on the firewall module, the SecuRemote / SecureClient needs to update/recreate the site in order to download the Split DNS information from the firewall module.

Note:
If you also wish to have the internal DNS traffic encrypted you will need to go to Global Properties > Remote Access and check the box to Encrypt DNS traffic. If you make this change you will need to install the Security Policy on the gateway and update the topology information on the client.
Reply With Quote
  #7 (permalink)  
Old 2006-01-10
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecureClient issues

That works with SecuRemote? Cool, love the documentation that told me it would only work with office mode :)

Thanks for posting!
Reply With Quote
  #8 (permalink)  
Old 2006-10-11
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: SecureClient issues

Please note that this procedure gives no hint to the client that this is happening in the background. It's all done inside the SecuRemote kernel and forwarded onto the VPN gateway.

What I mean is, there's no point in using commands like ipconfig on the client, because it won't show anything. Your best bet is to test it via ping FQDN.

It definitely works without Office Mode though.

Last edited by RobertGraham; 2006-10-11 at 10:58. Reason: added comment on ipconfig for clarity
Reply With Quote
  #9 (permalink)  
Old 2006-10-16
dramirez dramirez is offline
Junior Member
 
Join Date: 2006-10-16
Posts: 5
Rep Power: 0
dramirez has an average reputation (10+)
Default Re: SecureClient issues

Quote:
Originally Posted by chillyjim View Post
The licensing wasn't enforced well before R60.

That being said, you should complain to your local Check Point SE/Sales Rep that this should be part of SecuRemote and not a charged item. If enough people complain, TPTB will listen.
Trying to get Office Mode at lower price than SecureClient was never possible for me, I mean I wanted ONLY OM functionality and couldn't care less about SecureClient, CheckPoint Mexico tried to get me a deal, but they were unsuccessful.

I just upgraded to R61, and noticed R61 doesn't enforce the licensing for Office Mode, I was so happy, until I told my salesrep, he says in the future they could enforce the licensing check again and sadly I'll loose OM.

Free OM would be very nice of them, I second chillyjim!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0