CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-27
Member
 
Join Date: 2006-02-27
Posts: 67
Rep Power: 3
philuxe has an average reputation (10+)
Default Securemote and Office Mode

Hi all,


I have a question regarding SecuRemote with Office Mode.

Since I don't need the Desktop Security feature I wanted to use SecuRemote which is free, but Securemote doesn't support (at my known) Office Mode
which allow you to assign a IP address to the client. I need to assign an IP to each client because sometimes they use the same LAN addressing.

Trouble is when you install SecureClient on a computer it locks every access and thats not possible in my case since the VPN client
must be installed on employee home computers.

So question are :
1/ Is it possible to install Securemote as VPN client and make it working in Office Mode if I purchase the 25 SecureClient clients licence for the VPN-1 Gateway ????
2/ If YES, should I buy a second 25 SecureClient clients licence since the gateway is a IPSO cluster with two nodes ?



Hope I am clear

Thx
Reply With Quote
  #2 (permalink)  
Old 2006-02-27
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: Securemote and Office Mode

Hi Philuxe,

You're correct in that SecuRemote does not support Office Mode.

Unfortunately what I think this means for you is that the 'Office Mode' check box will never be available (grayed-out) in the Advanced Options section of SecuRemote and therefore the client will never ask for an Office Mode IP address from the Enforcement Module.

The answer to your question #1 is 'no' in this case.

Would it not be possible to use SecureClient and customise the desktop Policy so that their home access is not restricted (i.e. something like allow all in both directions)? Obviously you'd have to take account of risks to their computers, your organisation, etc.
Reply With Quote
  #3 (permalink)  
Old 2006-02-27
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Securemote and Office Mode

You can use windows native VPN client. This will provide Office Mode and no Desktop Security.


P.S. I hate Desktop Security. Do you want where I can join Desktop Security haters club? :)
Reply With Quote
  #4 (permalink)  
Old 2006-02-27
Member
 
Join Date: 2006-02-27
Posts: 67
Rep Power: 3
philuxe has an average reputation (10+)
Default Re: Securemote and Office Mode

Yes I can use the windows native IPSEC client.

But should I purchase secureclient licences for the gateway in order it assigns IP addresses to clients ???
Reply With Quote
  #5 (permalink)  
Old 2006-02-28
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Securemote and Office Mode

As far as I know you do not need policy server to assign IP addresses for native windows VPN clients. SecureClient license allow you to select Policy Server (the component where Centralized Policy we all hate stored)
Reply With Quote
  #6 (permalink)  
Old 2006-02-28
Member
 
Join Date: 2006-02-27
Posts: 67
Rep Power: 3
philuxe has an average reputation (10+)
Default Re: Securemote and Office Mode

Indeed it seems that is possible to use secureclient (with office mode) without any licence !!
I have tested if the first time with my eval licence then I have removed it and that still works :))))

Sergej > ur right, secureclient licence is only needed if we need to use Policyserver !!

I am not sure but that my conclusion and that I can see working here.
Reply With Quote
  #7 (permalink)  
Old 2006-10-16
Junior Member
 
Join Date: 2006-10-16
Posts: 5
Rep Power: 0
dramirez has an average reputation (10+)
Default Re: Securemote and Office Mode

Quote:
Originally Posted by philuxe View Post
Indeed it seems that is possible to use secureclient (with office mode) without any licence !!
I have tested if the first time with my eval licence then I have removed it and that still works :))))

Sergej > ur right, secureclient licence is only needed if we need to use Policyserver !!

I am not sure but that my conclusion and that I can see working here.
Just to let you know, my salesrep just told me that the license check for OM could be enforced at any time between versions... At this time on R61 the check is not done.
Reply With Quote
  #8 (permalink)  
Old 2006-10-17
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Securemote and Office Mode

Quote:
Originally Posted by dramirez View Post
Just to let you know, my salesrep just told me that the license check for OM could be enforced at any time between versions... At this time on R61 the check is not done.
Same thing I've been told. Bitch moan and gron that this function, along with NAT-T is included free with other vendors VPN client. Not that I really think it will help but you never know.
Reply With Quote
  #9 (permalink)  
Old 2006-10-27
Junior Member
 
Join Date: 2006-06-14
Location: AT
Posts: 20
Rep Power: 0
veste has an average reputation (10+)
Default Re: Securemote and Office Mode

Quote:
Originally Posted by Sergej View Post
As far as I know you do not need policy server to assign IP addresses for native windows VPN clients. SecureClient license allow you to select Policy Server (the component where Centralized Policy we all hate stored)
are there documents how to do this anywhere?
i could not find anything searching the web & cpug

regards, s.
Reply With Quote
  #10 (permalink)  
Old 2006-10-27
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Securemote and Office Mode

Quote:
Originally Posted by veste View Post
are there documents how to do this anywhere?
i could not find anything searching the web & cpug
All of the documentation is on the Check Point CD. You want to look in the VPN guide.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0