CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-04
Junior Member
 
Join Date: 2005-10-06
Location: Dallas, TX
Posts: 2
Rep Power: 0
achuang24 has an average reputation (10+)
Default SNX not working on R65

Would appreciate any help on this issue since we are getting ready to upgrade to R65 soon.

I have an test installation of SNX running on R65 SPLAT but cannot pull up the SNX login page from the external network. From the internal network or the DMZ network, it works fine when using IE to connect to HTTPS:\\gw.external.ip

Some facts:
1. Using the 30 day EVAL license
2. Management and enforcement module installed on same SPLAT R65
3. SPLAT webui set to 440 instead of 443
4. Visitor mode enabled for HTTPS on all interface
5. SSL Extender enabled in Remote Access section
6. On Management station, firewall GW object set to the external IP
7. SecureClient connects fine to firewall GW's external IP
8. Nothing is being reported on vpn debug

This should be a very simple install/setup but I can't get it to work. I wonder if this is a R65 issue.... Anyone running R65 yet?
Reply With Quote
  #2 (permalink)  
Old 2007-06-04
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SNX not working on R65

Yes I'm using R65 and SNX works fine.

You don't happen to have the default rules disabled in gobal properties do you?

Look for https drops in your log
Reply With Quote
  #3 (permalink)  
Old 2007-06-04
Junior Member
 
Join Date: 2005-10-06
Location: Dallas, TX
Posts: 2
Rep Power: 0
achuang24 has an average reputation (10+)
Default Re: SNX not working on R65

chillyjim, I don't see any https related rules in the global policy page. Also, there is no https recorded in the SmartView tracker when connecting from the external network.

I am pretty much allowing everything and logging everything in the test setup.
Reply With Quote
  #4 (permalink)  
Old 2007-08-29
Junior Member
 
Join Date: 2007-06-19
Location: Ohio, USA
Posts: 15
Rep Power: 0
RiverStone has an average reputation (10+)
Default Re: SNX not working on R65

I am seeing a similar problem. Have you by chance found a solution yet?

RiverStone
Reply With Quote
  #5 (permalink)  
Old 2007-08-31
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SNX not working on R65

If you try https://internal.ip.address instead is it still a problem?
Reply With Quote
  #6 (permalink)  
Old 2007-11-19
Junior Member
 
Join Date: 2007-07-31
Posts: 3
Rep Power: 0
smudger has an average reputation (10+)
Default Re: SNX not working on R65

maybe a silly question but...

is the Firewall object included in your encryption domain? my understanding is that it needs to be....


regards


Smudger
Reply With Quote
  #7 (permalink)  
Old 2007-11-19
Junior Member
 
Join Date: 2007-06-19
Location: Ohio, USA
Posts: 15
Rep Power: 0
RiverStone has an average reputation (10+)
Default Re: SNX not working on R65

First, let me apologize for not closing the loop on my portion of this post. Also, thanks for the response Smudger.

In our case, it turned out to be a licensing issue with LDAP authentication. We were licensed for LDAP on Connectra (this is "included" in the Connectra License) but not at FW-1. FW-1 (R65) was trying to handle the SNX authenication but was not licensed to do so. After working with TAC on a solution, the need to keep the project rolling backed us off of R62CM to R62 of Connectra which did not have the issue. My understanding is Checkpoint has a fix available now.

Achuang24, did you get your issue worked out?

RiverStone
Reply With Quote
  #8 (permalink)  
Old 2008-01-18
Senior Member
 
Join Date: 2007-06-05
Location: Canada
Posts: 188
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: SNX not working on R65

Yep, there's a special on-demand only hotfix for this

Check: sk33088

Issue is that Connectra comes with SmartDirectory but when you integrate management with the SCS, this gets disabled
Reply With Quote
  #9 (permalink)  
Old 2008-09-10
Junior Member
 
Join Date: 2007-12-19
Posts: 8
Rep Power: 0
yatzekcs has an average reputation (10+)
Default Re: SNX not working on R65

We had all setup the way it should be but SNX did not work. Called checkpoint just to find out that the 30 day evaluation did not include the SNX license. After gettting this sorted out, SNX works fine but we have some problems with the way it works. We would like to disallow our users from being able to browse the net and local network drives while they are connected through SNX but can't find an answer as of yet.

Yatzek
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 18:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0