CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > SSL Network Extender
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-05
dj_berkine dj_berkine is offline
Junior Member
 
Join Date: 2006-02-05
Posts: 11
Rep Power: 0
dj_berkine has an average reputation (10+)
Default SSL Network Extender problem

Hi all

I have a big problem with SSL network extender, basicaly i have a test envirement with checkpoint NG R55 HF12. the enforcement module and the smart center are in the same machine.

i did all the setup required to run SSL NE (visitor mode, office mode, user access...) and i connect successfuly to the gateway.
the problem appear after the authentication and the creation of the virtual interface . when i trie to ping a host behind the gateway i can see the packet encrypted sent to the gateway and then the gateway decript it and send it to the final host but there is no reply, my packet never come back. I'm almost sure it's a routing problem but everything looks normal
here is a windump done on the host that receive the ping you can notice that the gateway forward it but the host don't know how to go back to the remote peer (192.168.242.5)

22:35:56.692653 arp who-has 192.168.242.5 tell 192.168.242.20
22:36:20.794009 IP 192.168.242.5 > 192.168.242.20: icmp 40: echo request seq 18688
22:36:20.794130 arp who-has 192.168.242.5 tell 192.168.242.20
22:36:25.786631 IP 192.168.242.5 > 192.168.242.20: icmp 40: echo request seq 18944
22:36:25.786784 arp who-has 192.168.242.5 tell 192.168.242.20
22:36:31.527515 IP 192.168.242.5 > 192.168.242.20: icmp 40: echo request seq 19200
22:36:31.527621 arp who-has 192.168.242.5 tell 192.168.242.20
22:36:36.584388 IP 192.168.242.5 > 192.168.242.20: icmp 40: echo request seq 19456
22:36:36.584561 arp who-has 192.168.242.5 tell 192.168.242.20

Your help will be really appreciated

Thanks a lot

Berkine
Reply With Quote
  #2 (permalink)  
Old 2006-02-05
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: SSL Network Extender problem

It appears that you are using the same network range for your Visitors Mode or Office Mode as you are using for your internal network.

If your visitor mode or office mode IP range is the same as your internal Network then this will happen. Change to use a different IP range for your visitor mode or office mode.

If you use the same network for visitor mode or office mode when the destination will receive the packet and then try and route it back to the source. As it's on the same network it won't have to 'route' the packet because it's on the same network, thus it will arp for it waiting for a MAC address to send it to. As this IP address doesn't physically exist on this network then there will not be a reply for it to get a MAC address to send the packet back to. If you use a different network, then the destination will have to route the packet, usually to it's default route.
Reply With Quote
  #3 (permalink)  
Old 2006-02-05
dj_berkine dj_berkine is offline
Junior Member
 
Join Date: 2006-02-05
Posts: 11
Rep Power: 0
dj_berkine has an average reputation (10+)
Default Re: SSL Network Extender problem

Thanks a lot Lackie, I will try this and let you knwo

regards

Berkine
Reply With Quote
  #4 (permalink)  
Old 2006-02-06
dj_berkine dj_berkine is offline
Junior Member
 
Join Date: 2006-02-05
Posts: 11
Rep Power: 0
dj_berkine has an average reputation (10+)
Default Re: SSL Network Extender problem

Hi Lackie

Thanks a lot , now it's working fine, i thought in the first time that the firewall will respond to the arp that's why i didi it this way

Regards

Berkine
Reply With Quote
  #5 (permalink)  
Old 2006-02-07
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SSL Network Extender problem

FYI HFA 15 includes some SNX fixes, you might want to out the current HFA (17) before you put this in full production.

-jlh
Reply With Quote
  #6 (permalink)  
Old 2006-02-08
dj_berkine dj_berkine is offline
Junior Member
 
Join Date: 2006-02-05
Posts: 11
Rep Power: 0
dj_berkine has an average reputation (10+)
Default Re: SSL Network Extender problem

Thanks dude

will do

Regards

Berkine
Reply With Quote
  #7 (permalink)  
Old 2006-03-21
jimytri jimytri is offline
Junior Member
 
Join Date: 2006-01-05
Posts: 13
Rep Power: 0
jimytri has an average reputation (10+)
Default Re: SSL Network Extender problem

Hi Dj,

Could you let me how you enable the SSL Network Extender in CP?

Thanks and Regards,
Jim Qi
Reply With Quote
  #8 (permalink)  
Old 2006-03-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SSL Network Extender problem

See SK# 26564
Reply With Quote
  #9 (permalink)  
Old 2006-04-22
securityprof_1 securityprof_1 is offline
Junior Member
 
Join Date: 2006-04-22
Posts: 1
Rep Power: 0
securityprof_1 has an average reputation (10+)
Default Re: SSL Network Extender problem

Hi,

I had this same issue and changing the Office Mode IP pool to another range other than the internal range of the enforcement module worked, but only for SecureClient?.

Now SSL-NX user connects and authenticates, is supplied an IP address, DNS etc, SSL-NX user can ping the real and cluster IP addresses of the Enforcement modules internal interface but when trying beyond this to other hosts the taffic fails to return. I have no problems with SecureClient connecting to services beyond the Enforcement Modules own internal IP subnet.

Am running NGX R60 straight (no HFAs) in a Splatform HA cluster.

I have searched the KB and re-read the manual a number of times. Thoughts?

Thanks
Reply With Quote
  #10 (permalink)  
Old 2006-05-09
MrFlunch MrFlunch is offline
Junior Member
 
Join Date: 2005-10-27
Posts: 3
Rep Power: 0
MrFlunch has an average reputation (10+)
Default Re: SSL Network Extender problem

Hello,

I have the same problem with SNX on NGX platform
Connection and authentification are OK, but:

after authentification, my PC get an address ( that I have defined in the file $FWDIR/conf/ipassignment.conf) ,but I'm unable then from my PC to ping or ftp machines on the LAN protected by the Checkpoint Platfom.
I have tried first by defining an internal LAN address, and then with an address outside the LAN (eg 192.168.242.5), but it doesn't work.

Thanks for your help
Reply With Quote
  #11 (permalink)  
Old 2006-05-16
mathalas mathalas is offline
Junior Member
 
Join Date: 2006-05-16
Posts: 1
Rep Power: 0
mathalas has an average reputation (10+)
Default Re: SSL Network Extender problem

Hi,

I am not sure about your topology, but did you checked on the return route avilable on the device.
Reply With Quote
  #12 (permalink)  
Old 2006-05-16
MrFlunch MrFlunch is offline
Junior Member
 
Join Date: 2005-10-27
Posts: 3
Rep Power: 0
MrFlunch has an average reputation (10+)
Default Re: SSL Network Extender problem

I have a simple configuration with the enforcement module and the management module on the same splatform. (2 ethernet interfaces (input, output).

Someone advertised me to create a private LAN (192.168.x.x) in the dashboard and to use it for office mode (instead of the ipassignment.conf file).
It seems also necessary to manually define the VPN domain in the Topology page of the Dashboard and to indicate the local LAN.

I will try it asap on the production machine !
Any suggestion ?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:02.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0