CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-24
1q2w3e 1q2w3e is offline
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default NAT Issue - Urgent

I am in the process of setting up a Site to Site VPN with a remote client.

Usually we use our private ip address and then after the tunnel is through, remote users are able to ping through.

Now I have a new client who is unfortunately using the same private ip range as us.

My question is If I now add new public address to the node that only had an internal address , will it affect existing VPNs formed that has been using the private address?

e.g.

Node a = 172.16.14.1 and Node b = 172.16.14.2 these are the private addresses used with remote Client site to site VPN.

Now using the same Node a and Node b, I need to add public address to their NAT,

Node a = 172.16.14.1 also 90.172.12.1
Node b = 172.16.14.2 also 90.172.12.2

Will there be an issue?.

If there was going to be, how else can I achieve trying to set up VPN to another site which also have the same internal network as us?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2006-11-24
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 804
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: NAT Issue - Urgent

Depends on how you define your NAT rules. Set it up to not nat for the existing VPNs, that you don't want to break. (I think it's a check box on the VPN settings).

Now you know why those of us who've done this before insist on public addresses for all VPNs to third parties. Always use public IPs, and you don't run into these problems with clashes.
Reply With Quote
  #3 (permalink)  
Old 2006-11-24
1q2w3e 1q2w3e is offline
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Re: NAT Issue - Urgent

Thanks for your reply. Is this the

'Disable NAT inside the VPN community’

So does that mean, I can go to the site to site VPN of the existing VPN and click on 'Disable NAT inside the VPN community’ and they will not be affected. Leave it unselected for the new VPN and the Nated address will be used.

In fact I have just checked and most of them have this selected even though I am using private addresses. Is this correct?

Thanks

Last edited by 1q2w3e; 2006-11-24 at 09:15.
Reply With Quote
  #4 (permalink)  
Old 2006-11-24
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 804
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: NAT Issue - Urgent

Yes, that sounds right.

If you have it selected, and you're using private addresses, you're not going to have any problems. It's when you do want to do NAT that you need it unselected.
Reply With Quote
  #5 (permalink)  
Old 2006-11-27
1q2w3e 1q2w3e is offline
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Re: NAT Issue - Urgent

I have done this and I get the error

'encryption fail reason: Cannot identify peer for encrypted connection (VPN Error code 02)'

So I have had to go and remove the NAT address for the clients. How can I resolve this?

Luckily not all the VPN users had come onboard. Will the existing users have been affected by the above error message?

Thanks
Reply With Quote
  #6 (permalink)  
Old 2006-11-27
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 804
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: NAT Issue - Urgent

Check out your encryption domains - that sort of error message indicates that you don't have the remote encryption domain properly configured.
Reply With Quote
  #7 (permalink)  
Old 2006-11-27
1q2w3e 1q2w3e is offline
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Re: NAT Issue - Urgent

Thanks

Encryption domain. Yes I could see that is what the errors means, but how exactly, does it mean i have to make all our public addresses part of the encryption domain. ?

Where do I find this?
Reply With Quote
  #8 (permalink)  
Old 2006-11-27
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 804
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: NAT Issue - Urgent

Usually if I'm doing NAT in a Check Point VPN, I put both the real and public addresses in the local encryption domain.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:08.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0