CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-27
Roch_Greg Roch_Greg is offline
Junior Member
 
Join Date: 2008-03-21
Posts: 7
Rep Power: 0
Roch_Greg has an average reputation (10+)
Default SC only working when on Internal Network

Can anyone tell me what would cause SC w/om to work while connecting using a IP address from the Local Network (inside) but fail from the very same machine when using a dial-up connection or from the same machine but off the LAN?

Greg
Reply With Quote
  #2 (permalink)  
Old 2008-03-27
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 445
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: SC only working when on Internal Network

The IP Address of your firewall object is set to the Internal IP, and you have not set up link selection. Therefore the userc.C file has the IP to establish the client-site tunnel to as the internal IP, and can't reach it.

That's the most common mistake made here.
Reply With Quote
  #3 (permalink)  
Old 2008-03-28
Roch_Greg Roch_Greg is offline
Junior Member
 
Join Date: 2008-03-21
Posts: 7
Rep Power: 0
Roch_Greg has an average reputation (10+)
Default Re: SC only working when on Internal Network

Thanks for replying. I do have the link selection set to use the IP from the external Interface "Selected address from topology" setting.

When the product was initially installed several years ago eth0 was internal and eth1 was external. I switched that around so the External IP is on eth0 now but would like to know where does the fw pull it's IP address from?

It's really weird, in the test lab, I can do a clean install of SC and point it to the Internal IP of the Gateway and it'll do what's it supposed to. Authenticate, connect, download the topology and policy.

Take another machine and use a dial-up account and try to hit the external ip of the gateway w/SC and all I see it the logs are hits for fw1_topo. But there is no prompt for authentication so there is no encryption on that side.

Here's a snippet from the SC Service Log

fwclient_connect_ei: sic name for server 8a314941 is NULL.
peers addresses are 10.1.0.17
sic_client_do_connect: no server sic name supplied, server sic name is unknown.
[fwasync] fwasync_make_connection: 4149318a/264: dowait is -1 sock is 1208
fwuserc_exec_switch: finished command: 1.
[VPN] fwuserc_exec_switch: __end__ 10:54:54.93
fwasync_connected_failed: 1208 from exception: The access code is invalid.
fwclient_connected: connection failed
[VPN] fwuserc_post, command=6 (0x6)
[VPN] fwuserc_post: Forwarding the posted message to the GUI.
[Communication] Add Command to RPC table: 53
[Communication] Remove Command from RPC table: 53

Greg
Reply With Quote
  #4 (permalink)  
Old 2008-03-28
Roch_Greg Roch_Greg is offline
Junior Member
 
Join Date: 2008-03-21
Posts: 7
Rep Power: 0
Roch_Greg has an average reputation (10+)
Default Re: SC only working when on Internal Network

Okay, I found under the gw's General Properties where the IP address is assigned. It's the same as it has always been. The Public IP of the GW.

Greg
Reply With Quote
  #5 (permalink)  
Old 2008-03-29
Roch_Greg Roch_Greg is offline
Junior Member
 
Join Date: 2008-03-21
Posts: 7
Rep Power: 0
Roch_Greg has an average reputation (10+)
Default Re: SC only working when on Internal Network

Well I found and fixed my problem today. I'm ashamed at why it took me two weeks of troubleshooting to figure something so silly out.

I guess with 12+ years in the field under my belt and a couple fancy pants College Degree's one can still lose track of the basics of troubleshooting and get stumped on the simple stuff.

Now that Secure Client is connecting I still need to get traffic routed (can't see my internal network yet) but at least the major headache is solved.

Thank you everyone who took the time to answer and read my post

Greg
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0