CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-09
checkisco checkisco is offline
Junior Member
 
Join Date: 2006-04-09
Posts: 3
Rep Power: 0
checkisco has an average reputation (10+)
Default How to configure SSL extender for NGX on Nokia platform

h everyone I just upgrade to NGX version, We already have secure remote users configured, I would like to test the new SSL extender fonctionality.

could someone help me about the installation procedure (I'm new in this thing)

This my configuration :

Checkpoint version : NGX 60

MANAGEMENT STATION OS : windows 2000
Enforcement modules : 02 Nokia IP530 on VRRP mode.

Thanks a lot,
Reply With Quote
  #2 (permalink)  
Old 2006-10-25
giallorossi77 giallorossi77 is offline
Junior Member
 
Join Date: 2006-10-24
Posts: 6
Rep Power: 0
giallorossi77 has an average reputation (10+)
Default Re: How to configure SSL extender for NGX on Nokia platform

Hi,
I followed the instructions reported on the official CP documentation but I'm not able to make it work.
Systems:
nokia ip350
NGX hfa04 with distributed installation (CMA is on P1).

After changing Voyager port to 444, the nokia answers to 443 port request, but I'm not able to get the SNX login page.
It seems (looking at the vpnd.elg) that the Vpn-1 and remote peer cannot negotiate TCP session paramters.

Any Idea?

3056128]@fw[24 Oct 9:41:48] async_mux_data_handler: Try connection type TCPT with 0 bytes
[vpnd 529 3056128]@fw[24 Oct 9:41:48] async_mux_data_handler: Connection type got 0, needs 4 bytes
[vpnd 529 3056128]@fw[24 Oct 9:41:48] async_mux_data_handler: Wait for 4 more bytes
[vpnd 529 3056128]@fw[24 Oct 9:41:48] fwasync_connbuf_realloc: reallocating 0 from 0 to 1028
[vpnd 529 3056128]@fw[24 Oct 9:41:48] async_mux_data_handler: Try connection type TCPT with 4 bytes
[vpnd 529 3056128]@fw[24 Oct 9:41:48] async_mux_data_handler: No connection types matched -- failed!
Reply With Quote
  #3 (permalink)  
Old 2006-12-07
BruceR BruceR is offline
Junior Member
 
Join Date: 2006-04-26
Posts: 21
Rep Power: 0
BruceR has an average reputation (10+)
Default Re: How to configure SSL extender for NGX on Nokia platform

checkisco we are running almost exactly the same hardware/software.

2 x IP560's NGX R60 HFA_04 & Management station on Win 2003 and NGX R60 HFA_04

It's quite well documented in CheckPoint_NGX_VPN_Guide.pdf

Make sure the SNX licences are on the management station, NOT the enforcement module. This is what caught me out. Also if you are running in Trad mode, the enforcement module object must be in the remote access community.

Run a VPN debug and check vpnd.elg for errors. Good luck
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:51.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0