CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-15
20100 20100 is offline
Junior Member
 
Join Date: 2006-10-18
Posts: 13
Rep Power: 0
20100 has an average reputation (10+)
Default Is SSL Network Extender the anwer?

Hi,

Not sure if it is the right place within the forum to ask:

We have site to site VPN with partners, but only allow traffic from our office to theirs.

From time to time we have staff spending time within the partner offices, requiring access back to our office.

Access to our office is only provided (so far) using SecureClient.

However, in most of the cases, SecureClient does not work, as the Firewall is confused between the SecureCLient VPN and the site-to-site VPN link already established between the 2 firewalls (I gather that the remote Secureclient is hiding behind the IP of the partner's firewall).

Is there anyway to get this going?

The other idea, what perhaps to implement SSL Network Extender. At first I thought that it would work with a Web server (different IP from the firewall), but when reading more, it looks like we are talking about a web server installed on the firewall itself, which could cause the same issue
I am right or will it work?

The other idea, would be perhaps to install a Citrix Server for remote access via web access.

Are there any other (better) ways to achieve what we want to do?

Thanks for sharing your ideas

Vincent
Reply With Quote
  #2 (permalink)  
Old 2008-04-15
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Is SSL Network Extender the anwer?

If I read this correctly you have people at a partner site which you have a s2s VPN connection with. You want to provide client2site VPN for these folks and it will not work.

WOW, I'm suprised I haven't ran into this before...

SNX on the firewall gateway will not help, you will have the same problems.

SNX on a different gateway or Connectra (which includes SNX) would help if configured correctly.

Depending on what you need to do while remote, Citrix may be a better answer, but Connectra will give you full VPN functionality as well as HTTP portal for your users.
Reply With Quote
  #3 (permalink)  
Old 2008-04-15
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Is SSL Network Extender the anwer?

I've run into this before. In some cases, Visitor mode worked. With the gateway listening on 443, it seems to traverse pretty well.

I have a safe@office at my house with a site to site at work. Same circumstances, pre-existing tunnel. I cannot use SecureClient from my house except in Visitor mode.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #4 (permalink)  
Old 2008-04-16
20100 20100 is offline
Junior Member
 
Join Date: 2006-10-18
Posts: 13
Rep Power: 0
20100 has an average reputation (10+)
Default Re: Is SSL Network Extender the anwer?

Thanks guys. Looks like Connectra or Citrix are the answers. Not cheap solutions for both of them. I will have a closer look at both.
Reply With Quote
  #5 (permalink)  
Old 2008-04-17
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Is SSL Network Extender the anwer?

I though everyone knew that if you have a Site-2-Site VPN then you can't use a SecureClient VPN between the same two places.
Reply With Quote
  #6 (permalink)  
Old 2008-04-17
abusharif abusharif is online now
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Is SSL Network Extender the anwer?

Quote:
Originally Posted by 20100 View Post
Thanks guys. Looks like Connectra or Citrix are the answers. Not cheap solutions for both of them. I will have a closer look at both.
If you will be looking at connectra i suggest that you take a look at Juniper SA ssl appliances, which are, according to me, much much (can i add another much?) better then connectra in any aspect.

Now i will go and hide ;)
Reply With Quote
  #7 (permalink)  
Old 2008-04-17
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Is SSL Network Extender the anwer?

Quote:
Originally Posted by abusharif View Post
If you will be looking at connectra i suggest that you take a look at Juniper SA ssl appliances, which are, according to me, much much (can i add another much?) better then connectra in any aspect.

Now i will go and hide ;)
No need to hide, but please do start another thread on why you think this. I'm not disagreeing (or agreeing) at this point. I'm just always interested in why people like one product over another.

***Disclaimer -- I sell Check Point and not Juniper***
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0