CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-20
Junior Member
 
Join Date: 2007-07-03
Posts: 16
Rep Power: 0
Jay_D has an average reputation (10+)
Default SecureClient behind a VPN peer

Hi,

consider this scenario: main site running NGX R62. Branch site has a site-to-site VPN on a Safe@ with the main site. A laptop user with SecureClient (with config for the main site) goes to the branch site and wants to access the main site.
As there is a site-to-site no SecureClient connection is needed but for some reason he cannot access the main site. Auto-Connect is disabled.
The strange thing is that he can access the main site if he stops VPN-1 SecureClient (right click icon in systray and choose stop).

So my question is: why is SecureClient interfering if we didn't click connect ourselves? I would like to have SecureClient active when I want it (for example in a hotel) and just sitting there when I am at the branch office.

If this is the basic behaviour then I'd prefer to have SecureClient on manual startup but I can't figure this out without giving the user admin rights.

Any feedback is appreciated.
Kind regards,
JD.
Reply With Quote
  #2 (permalink)  
Old 2008-05-20
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 99
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default Re: SecureClient behind a VPN peer

Theres a few things here that you can look at:

1. Are you running a desktop policy that defines a strict firewall rulebase?
2. Is the branch site included in the desktop rulebase as being allowed?
3. Have you read and understood the following section of the VPN Admin Guide "How to Prevent a Client Inside the Encryption Domain from Encrypting"

Give those things a look over and let us know how you get on.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 14:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0