CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-03
Junior Member
 
Join Date: 2006-02-17
Posts: 4
Rep Power: 0
rasoftware has an average reputation (10+)
Default Remote Access VPN problem

I have setup VPN on VPN-1 Server, basic access using SecuRemote client.

I am able to establish the connection from my laptop and it connects ok. I am not able to access any of my network through the connection.

The client doesnt give an IP address to my machine so what address do I appear to be coming from to a server on the network?

Internal network 192.100.150.0/24

My Home address is 192.100.152.0/24 so dont see conflict there.

Last edited by rasoftware; 2006-03-03 at 05:57.
Reply With Quote
  #2 (permalink)  
Old 2006-03-03
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: Remote Access VPN problem

That's correct, you don't get assigned an IP address unless using Secure Client and Office Mode.

Therefore you're client 'exists' as 192.100.152.x, but on the inside interface of the firewall.

All you need is a security rule along the lines of:

SOURCE DESTINATION VPN Action

remote_access_group internal_network Remote Access Accept

This is fine for a simple setup.

Give that a go, it should work as it sounds like you have the Remote Access Community setup correctly.
Reply With Quote
  #3 (permalink)  
Old 2006-03-03
Member
 
Join Date: 2006-01-09
Posts: 72
Rep Power: 3
ddarby1 has an average reputation (10+)
Default Re: Remote Access VPN problem

The rule post wasn't that clear:

SOURCE: remote_access_group

DESTINATION: internal_network (or host, etc.)

VPN: Remote Access

Action: Accept
Reply With Quote
  #4 (permalink)  
Old 2006-03-06
Junior Member
 
Join Date: 2006-02-28
Posts: 17
Rep Power: 0
stefan73er has an average reputation (10+)
Default Re: Remote Access VPN problem

hi,

i have SecuRemote Clients that connecting to my checkpoint. All of them get assigned a private IP Address from a defined IP-NAT-Pool. So i can route traffic back to these private address range. But sure there is nothing like a virtual network adapter that have this ip.

cheers,

Stefan
Reply With Quote
  #5 (permalink)  
Old 2006-04-25
Member
 
Join Date: 2006-03-14
Posts: 96
Rep Power: 3
avilT has an average reputation (10+)
Default Re: Remote Access VPN problem

Make sure your internal network(192.100.150.0/24) routes the traffic thru the VPN Gateway. Use Firewalls interface as the gateway on internel network.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 03:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0