CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-04
tdvit tdvit is offline
Senior Member
 
Join Date: 2005-08-30
Posts: 143
Rep Power: 4
tdvit has an average reputation (10+)
Default Remote access community

Hi,

Is it possible to have more than one remote access community in CP?

Looks like a no?

Have a requirment for one user who needs access to one server and would not be at a fixed IP. I have suggested SSL VPN appliance but wondered was there any other way to do this in checkpoint?

thanks
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #2 (permalink)  
Old 2008-04-04
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Remote access community

It seems you can't which is a bit crap to be honest.

If you use Traditional mode you can define the Client-to-site VPNs exactly as you want, so that might be an option.

You can still use one single community and then use the rules to create granularity.
Reply With Quote
  #3 (permalink)  
Old 2008-04-10
coldark coldark is offline
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: Remote access community

Personally I would not opt to switch to traditional mode, because Simplified mode offers much more capability and seems to have been developed more by CheckPoint than the old Traditional Mode.

As Mario suggests there is NO WAY to have more than 1 Remote Access VPN Community. But I also dont see this as an issue, because the Rulebase can explicitly determine which users are allowed to go to which destinations and for which services (the granularity that MarioL mentions).

example:

I have a Remote Access Community containing 3 Gateways:
__ FWOslo - with NetOslo as the VPN Domain,
__ FWRome - with NetRome as the VPN Domain,
__ FWToronto - with NetToronto as the VPN Domain
and 3 Usergroups
__ UGRome,
__ UGRome,
__ UGToronto.

I can now configure my rules something like this:

UGRome@any | NetRome | Remote Access | any | Accept
UGOslo@any | NetOslo | Remote Access | any | Accept

and so on.

In your case you could add a usergroup UGwhatever (containing your one customer) and add a rule

UGWhatever@any | SpecificServer | RemoteAccess | RequiredServices | Accept

ofc this also assumes that your SpecificServer is in the vpn domain of one of the gateways in your remote access community.

Last edited by coldark; 2008-04-10 at 03:51. Reason: Clarification
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:40.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0