CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-21
Senior Member
 
Join Date: 2006-03-14
Posts: 100
Rep Power: 3
avilT has an average reputation (10+)
Default IP address for Firewall Object

When creating firewall object what IP (internal/external) should we use? I used external interface IP, but when I select get IP address, it acquires internal IP? FW running on a wndows PC with dual NIC, to which IP address the hostname will be bound? Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-04-21
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP address for Firewall Object

Hi,

Normally, we use internal IP and it is recommended to do so. Is your license bind to internal IP or external?

Regards,

Al
Reply With Quote
  #3 (permalink)  
Old 2006-04-25
Senior Member
 
Join Date: 2006-03-14
Posts: 100
Rep Power: 3
avilT has an average reputation (10+)
Default Re: IP address for Firewall Object

Its bound to external IP. Is there any specfic guidelines on this?
Reply With Quote
  #4 (permalink)  
Old 2006-04-25
Senior Member
 
Join Date: 2005-12-12
Location: Malaysia
Posts: 122
Rep Power: 0
pop_alex has an average reputation (10+)
Default Re: IP address for Firewall Object

Hi,

No. But it is recommended to bind license to internal rather public IP. If you want to change the existing IP to new internal IP, you may do so by accessing Check Point's usercenter and change it online. It will generates a new license for you with new IP.

Regards,

Al
Reply With Quote
  #5 (permalink)  
Old 2006-09-26
Member
 
Join Date: 2006-01-04
Location: Germany
Posts: 36
Rep Power: 0
Tetaworx has an average reputation (10+)
Send a message via ICQ to Tetaworx
Default Re: IP address for Firewall Object

Hello,

are you using site2site VPN's with a FW-1 gateway with an internal ip defined?

We're, too, using the internal IP für the firewall(-cluster-)object and had no problems with that until now.

But now we've a problem with a remote site2site VPN, because our gate uses the internal IP as ID in the IPSec negotiation. The remote partner does of course not recognize this internal IP and sends an

"Notify Payload

Next Payload: NONE
Reserved: 0
Length: 00 1c (28)
DOI: 00 00 00 00 (0)
ProtID: 1
SPI Size: 16
Notify Type: 18 (INVALID-ID-INFORMATION)
SPI:
ef a0 bb b4 2f 0b 0a 8c f3 d5 90 69 23 84 ea
62 "

Has anyone ever hat this problem, too?

Thanks in advance,

Dennis Breithaupt
Reply With Quote
  #6 (permalink)  
Old 2006-09-26
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: IP address for Firewall Object

Yes, I've seen that problem. If you're using pre-NGX, you need to use the external IP as the primary IP of the firewall object. Normally this is not a big deal to change, since your licenses should be central anyway.

If you're using NGX, the link-selection options should let you do what you want without changing the firewall IP.
Reply With Quote
  #7 (permalink)  
Old 2006-09-26
Member
 
Join Date: 2006-01-04
Location: Germany
Posts: 36
Rep Power: 0
Tetaworx has an average reputation (10+)
Send a message via ICQ to Tetaworx
Default Re: IP address for Firewall Object

Hi,

we're using NGX (R60_HFA03).

Outgoing Route Selection is on "Operating system routing table", Source IP address settings is on "Automatic (derived from method of IP selection by remote peer)".

We need this setting, because some of our remote-users connect to an "internal" interface of our firewall, so we can't set this "hard" to "Manual: Main IP address".

Nevertheless the "Source Adress" of our IKE-pakets is correct, the external IP of our gateway. But the "ID" in the payload of the IPSec-pakets is the wrong one, the internal IP.

I don't see any option to manipulate this "ID" itself.

Further hints?

Thanks!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:06.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0