CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-03
futureechos futureechos is offline
Junior Member
 
Join Date: 2007-08-03
Posts: 13
Rep Power: 0
futureechos has an average reputation (10+)
Default Access to Dashboard / Tracker via VPN

I'm having a problem remotely managing my firewalls externally via a VPN.

All works fine when onsite, when coming in via VPN I get the 'cannot connect, make sure you are a GUI client.' error

- I have a fixed IP when I VPN in, this is a GUI client.
- I can telnet to the firewall manager on port 18190 when connected via VPN, but still it refuses.
- Tracker shows my VPN fixed IP allowed access on port 18190

Any ideas? Any logs I can look at on the fwm when in expert mode?

thanks.
FE
Reply With Quote
  #2 (permalink)  
Old 2007-12-03
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 496
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Access to Dashboard / Tracker via VPN

Guess 1 would be NAT - make sure your IP address isn't being NATted.

Guess 2 would be implied rules (you are logging implied rules, right?). Check in your logs to see if your port 18190 traffic is being blocked because it's being sent in clear and the other side is expecting encrypted (or vice versa).

The solution I've always used for this is setting up an SSH session to the SmartCenter and using SSH port forawarding. Works like a charm!
Reply With Quote
  #3 (permalink)  
Old 2007-12-03
futureechos futureechos is offline
Junior Member
 
Join Date: 2007-08-03
Posts: 13
Rep Power: 0
futureechos has an average reputation (10+)
Default Re: Access to Dashboard / Tracker via VPN

Quote:
Originally Posted by Thorpuse View Post
Guess 1 would be NAT - make sure your IP address isn't being NATted.

Guess 2 would be implied rules (you are logging implied rules, right?). Check in your logs to see if your port 18190 traffic is being blocked because it's being sent in clear and the other side is expecting encrypted (or vice versa).

The solution I've always used for this is setting up an SSH session to the SmartCenter and using SSH port forawarding. Works like a charm!
Thanks for the reply.

Good ideas!

The VPN is held on externally to the checkpoint ones, so its coming in clear after decryption
It's not NATing, I can see 18190 traffic going through.

Tunnelling over ssh, that's a cool idea. I'll have to try that.
Reply With Quote
  #4 (permalink)  
Old 2007-12-03
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Access to Dashboard / Tracker via VPN

Also remember that officially Check Point do not support SmartCenter Access over a SecureClient VPN.

Either ensure that the SMARTCenter is NAtted to a public address and connect to that from a specific host, or make a connection as suggested already.
Reply With Quote
  #5 (permalink)  
Old 2007-12-03
futureechos futureechos is offline
Junior Member
 
Join Date: 2007-08-03
Posts: 13
Rep Power: 0
futureechos has an average reputation (10+)
Default Re: Access to Dashboard / Tracker via VPN

Quote:
Originally Posted by mcnallym View Post
Also remember that officially Check Point do not support SmartCenter Access over a SecureClient VPN.

Either ensure that the SMARTCenter is NAtted to a public address and connect to that from a specific host, or make a connection as suggested already.
OK, thanks for the info.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:04.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0