CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartCenter Server (Formerly Management Server)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-25
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default SmartCenter and NAT

Can someone help me with this issue?

I have a SmartCenter NGx R65 with HFA_02 running on SPLAT.
the IP address of the SMC box is 192.16.1.10/24. This SMC
box is sit behind Cisco router facing the Internet.
IP address of the Cisco router is 192.168.1.1/24 and
4.2.2.2/24 respectively.

I natted the SMC box to 4.2.2.3 on the Cisco router
so that User(s) on the Internet can access the SMC with
the SmartDashboard:

ip nat inside source static 192.168.1.10 4.2.2.3


From the Internet, when I launch the SmartDashboard,
I get the fingerprint but then SmartDashboard says:
"failed to launch application". I noticed that this
issue happened since NGx R61 and higher. It does not
matter if I replace the Cisco device with a Checkpoint
firewall, I still get the same error.

If I repalce the SmartCenter NGx R65 with SmartCenter
NG with AI R55, I can connect fine over the Internet.

Is this a new feature of NGx or is this a bug?

If anyone would be willing to help me out by testing
this with me? I can open my firewall so that you can
try to log into my SmartCenter over the Internet, please
send me a private message. Thanks.
Reply With Quote
  #2 (permalink)  
Old 2008-01-25
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: SmartCenter and NAT

How about not nat'ing on the cisco, and instead give the management box the 4.2.2.3 address on one of it's interfaces?
Reply With Quote
  #3 (permalink)  
Old 2008-01-25
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

That would be an easy solution. Unfortunately, real-life situation does
not work out that way. I wish it was that simple.
Reply With Quote
  #4 (permalink)  
Old 2008-01-25
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: SmartCenter and NAT

Curious... Why?
Reply With Quote
  #5 (permalink)  
Old 2008-01-25
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

Because the customer is already setup the box this way with
private IP address and they are not going to change it. They
want to give Read-only via SmartDashboard to an auditor outside
the company access to the SMC. NO VPN.

The point is that it works perfect in NG w/ AI R55 but not in NGx.
I couldn't find any documentation that can said it broke in NGx.
Reply With Quote
  #6 (permalink)  
Old 2008-01-25
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: SmartCenter and NAT

Ahh... Well, that is no good. I could think of some possible solutions, but I think they would be a mickey mouse way of doing things...
Reply With Quote
  #7 (permalink)  
Old 2008-01-25
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SmartCenter and NAT

On the SmartCenter object, is there a check box about NATting the control connections? Seems to me there is (or was). Try looking at it.

Ray
Reply With Quote
  #8 (permalink)  
Old 2008-01-25
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

That is only possible if the SmartCenter is behind a Checkpoint firewall,
NOT a Cisco IOS or Pix. By the way, this option is also available in R55
as well. That is only good if the SMC has to perform SIC with the
Enforcement Modules. This option is no good for CPMI connection because
they use tcp port 18190.
Reply With Quote
  #9 (permalink)  
Old 2008-01-26
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SmartCenter and NAT

It's not relevant in this case, but are you sure about the SIC thing? SIC is name-based. I thought it was for control connections.

Maybe that check box builds a new implied rule or a new NAT rule. If so, perhaps that would give you a clue as to how to configure the router.

Quote:
They
want to give Read-only via SmartDashboard to an auditor outside
the company access to the SMC. NO VPN.
SmartPortal would be a better solution. I don't know what the license costs, though.

Ray
Reply With Quote
  #10 (permalink)  
Old 2008-01-26
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

Hi Ray,

"It's not relevant in this case, but are you sure about the SIC thing? SIC is name-based. I thought it was for control connections."

I am very certain about this. This "control connections" exists in NG with AI
and higher so that the firewall and SmartCenter are aware that the
SMC is behind a "checkpoint" NAT device. In NG Feature Pack 3, there
was no such option and you have to use the "dummy" object approach.

I remembered this quite well because I had a huge fight with Checkpoint
Professional services about this. A checkpoint professional service came
in and deploy Provider-1 for us back in 2004 and he assigned private
address to the P-1/CMA box and that the box sits behind a Cisco Pix
firewall doing NAT. After a week of agony, I told the Checkpoint Professional
service to go F! himself and I rebuilt the P-1 box with routable public IP.
Company wasted about 50k on CP professional and nothing to show for.

Oh well...
Reply With Quote
  #11 (permalink)  
Old 2008-01-26
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: SmartCenter and NAT

Just curious if you have maybe tried this.. I have no idea if it will work, and have not tested it.. But....

What about creating a host file entry on the machine connecting to the smartcenter server, and match the name in the host file, to the name you have configured the smartcenter as. Then connect via the name, instead of the ip... Perhaps the gui client is seeing that the ip entered does not match a valid interface on the smartcenter, and maybe if using a name instead, it will see the match...

Probably wont work, but just a thought...
Reply With Quote
  #12 (permalink)  
Old 2008-01-26
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

I already tried that scenario before posting that question in the group.

On the other hand, I have another Linux box with private IP on the same
network as the SMC. from my windows machine on the Internet,
I ssh'ed into the Linux box, and I then enable port-forwarding on
the Linux box. From my windows box, I then use the Smartdashboard
to connect to the SMC with the 127.0.0.1 IP address. That method works.
However, the SMC think the Linux is connecting to it, not my windows
machine. Therefore, there is NO NAT in this situation.

With NAT, it does not work, either with IP or hostname.
Reply With Quote
  #13 (permalink)  
Old 2008-01-26
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 861
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: SmartCenter and NAT

After some testing, it turns out it's not a NAT issue at all. It looks like some kind of weird problem with the Provider-1 Multi-Domain GUI. The plain old R65 GUI works most of the time. The shortcut to start the P-1 GUI is

Target: "C:\Program Files\CheckPoint\Provider-1\R65\CPLauncher.exe" 9

Start in: "C:\Program Files\CheckPoint\Provider-1\R65\"

If you go to a command prompt in "C:\Program Files\CheckPoint\Provider-1\R65\" and run

cplauncher 9 <Enter>

it works fine from the Internet. Go figure.

The numeric parameter tells it which program to launch. My guess is cplauncher.exe is not respecting the "Start in" parameter. Why it works when run from the LAN is what's weird.

Ray

Last edited by RayPesek; 2008-01-26 at 14:41.
Reply With Quote
  #14 (permalink)  
Old 2008-01-26
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: SmartCenter and NAT

Couple of things to try -

1. Get a packet trace on tcp/18190 and see what source IP the incoming connections are. I regularly use Office Mode and IPAssignment to manage my SmartCenter remotely, and I had to make sure the OM NATted address was in the GUI Clients list.

2. For a test only, add "Any" to the GUI clients list, and test. That will tell you if it's the ACL on the SmartCenter that is causing the problem.

3, If the Any fails, test an SSH connection from the same location, just to make sure that routing and NAT are all working properly, and it's not a general connectivity issue.

FWIW - the SSH/Port Forwarding technique is a great way to get around a lot of these issues, and I tend to use that a lot. That could be a pretty effective workaround.
Reply With Quote
  #15 (permalink)  
Old 2008-01-26
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: SmartCenter and NAT

Here is a summary of my test:

1- I have Provider-1 GUI R65 with HFA_01 and SmartConsole R65 with
HFA_01 on my laptop. I also have P-1 GUI R55 and SmartConsole R55
on my laptop as well.

2-I specify "Any" GUI clients in the Provider-1, as confirmed in the $MDSDIR/conf/mdsdb/cp-gui-clients.C file:
:domain ()
:gui_client_type (any)
:ipaddr ()
:ipaddr2 ()
:mds_client (true)
:netmask ()
:value (any)
)

3- My laptop sit behind a Cisco Pix 8.0(3) firewall with:
nat (inside) 1 0 0
global (outside) 1 interface
access-list test permit ip any any log
access-group test in interface outside

In other words, the Pix will "hide" NAT ALL outbound traffics

4- The P-1 R65 box has a private address of 192.168.1.1 and it is
NAT'ed to 4.2.2.2 on the Cisco IOS router. There is a CMA
with an IP address of 192.168.1.10 and it is NAT'ed to
4.2.2.3 by the cisco router as well.

From my laptop, I can connect to 4.2.2.3 with Smart Dashboard/Tracker.
From my laptop, I can NOT connect to 4.2.2.2 with Provider-1 GUI,
From my laptop, I can NOT connect to 4.2.2.2 via the command line
"cplauncher 9" as suggested by Ray. I always get "Failed to launch
application".

I replaced the P-1 R65 box with P-1 R55 box and I CAN connect
to 4.2.2.2 with the P-1 R55 GUI and 4.2.2.3 with Smart Dashboard/Tracker
R55 GUI

This is definitely different when Ray tested the connection with me. I could
see him connect to my Provider-1 R65 with the P-1 GUI.

This is really weird. tcpdump showed everything is normal and that
the P-1 box is seeing traffics coming from the Pix's external interface,
hide NAT. Everything being equal, it tells me that Provider-1 NGx R65
GUI has issues, I think
Reply With Quote
  #16 (permalink)  
Old 2008-01-26
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: SmartCenter and NAT

edit : Didn't read properly what was below. I think you're right, P-1 R65 seems to have GUI issues. looks like a job for CP support.
Reply With Quote
  #17 (permalink)  
Old 2008-03-30
zahaha04 zahaha04 is offline
Junior Member
 
Join Date: 2008-03-09
Posts: 3
Rep Power: 0
zahaha04 has an average reputation (10+)
Default Re: SmartCenter and NAT

Have you defined the External IP as a Gui client in SmartCenter?Just a thought.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:50.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0