CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-12
djdani djdani is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 2
Rep Power: 0
djdani has an average reputation (10+)
Default Remote Site

Hi there I am new in this forum
I have a problem that I need help for
I have my main Office Net & 2 additional sits that I connect them to my network via IPVPN device that connect directly to my network

In My Office Network I have The Checkpoint NGX R60
For example this is my network 10.0.0.1 with the subnet of 255.0.0.0 my getwae is 10.0.0.1
The getaway is nut my firewall
The getaway is my eSafe 10.0.0.1
& the getaway to my eSafe is The Firewall

And My IPVPN that is connected to my network has the IP OF 10.0.0.254 Subnet
255.0.0.0 Getaway 10.0.0.1

My First site ip is 10.0.1.0 subnet 255.0.0.0 getaway 10.0.0.254 Act As DHCP
The second site ip is 10.0.2.0 subnet 255.0.0.0.getway 10.0.0.254 Act as DHCP

The Esafe Getaway have route to the sits to allow me remote access
If needed

So far everything is working fine the clients from both sits can log on to my DC and get everything from my network
And So Can I
The problem is to allow the clients internet access
How do I configure the firewall to do that
Reply With Quote
  #2 (permalink)  
Old 2008-03-12
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 276
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Remote Site

The first thing you need to do is get rid of the 8 bit mask on 10.x.x.x. as 10.0.1.0/8 is in the same network as 10.0.2.0/8. I HIGHLY recommend reducing the size of those subnets to a size more appropriate to the number of hosts residing in each subnet. If you manage both sites, your first step should be reducing those to eliminate subnet overlap. SecureClient/SecureRemote will not route properly with this overlap.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2008-03-12 at 07:35.
Reply With Quote
  #3 (permalink)  
Old 2008-03-12
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Remote Site

Very true, you really need to work on improving the way you are currently using the address space.

Regarding Internet access, while connected, the users can either access the Internet directly or route the traffic through the gateway. Both require diferent configs.
Reply With Quote
  #4 (permalink)  
Old 2008-03-13
djdani djdani is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 2
Rep Power: 0
djdani has an average reputation (10+)
Default Re: Remote Site

Thanks for the reply but I manage to solve the problem
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0