CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-24
Junior Member
 
Join Date: 2006-03-20
Posts: 4
Rep Power: 0
pbhavsar has an average reputation (10+)
Default Spoofing and VPN conflict.

I have two firewalls in site-to-site VPN with following settings

10.10.10.1/24 (Anti-Spoofing domain 10.0.0.0/8, VPN domain 10.10.10.0/24)
|
111.111.111.1 FW1
|
222.222.222.2 FW2
|
10.20.20.1/24 (Anti-Spoofing 10.20.20.0/24, VPN domain 10.20.20.0.24)

I created site to site VPN between FW1 and FW2. If i try to connect PC 10.20.20.20 (behind FW2) from the PC 10.10.10.10 domain (behind FW1). I can not communicate. I get follwing log on FW1
1. Source 10.10.10.10, Dest. 10.20.20.20, interface internal, encrpted packet, accepted
2. Source 10.10.10.10, Dest. 10.20.20.20 interface external, packet drop

If I add 10.0.0.0/8 on "don't check for Anti-spoofing" of external interface of FW1, VPN works. But, I am opening my network for external people to spoof in to my network. Is there any other solution to fix my VPN problem.

FYI: I can not change my spoofing network on FW1 from 10.0.0.0/8.
Reply With Quote
  #2 (permalink)  
Old 2006-03-25
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Spoofing and VPN conflict.

Well, the problem that you are having is because you have the 10.0.0.0/8 as the antispoofing on your internal network. It's seeing traffic from the remote network (10.20.20.1) and thinks it's a spoofed address because it's coming in the wrong interface as it's expecting it from your internal network as this is how you have the antispoofing group set up.

You have two choices... you can not do antispoofing or you can change your antispoofing group. As not turning off antispoofing is a risk you are left with changing your antispoofing group.

Good news is that there are two ways to do this:

1. Make a group with all of your internal networks and then use that group object for the antispoofing.

2. Create a group with exclusing object and use the 10.0.0.0/8 network and exclude the 10.20.20.0/24 network. This will get the same as what you currently have now but exclude the 10.20.20.x network from your internal network antispoofing and thus allow it through your firewall.

Now if you physically have a 10.20.20.x network on your internal network, you will have other problems with the VPN other than antispoofing.
Reply With Quote
  #3 (permalink)  
Old 2006-03-25
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Spoofing and VPN conflict.

Does "wire mode" VPN checks for antispoofing? If wire lode skip antispoofing you can enable this function for you tunnel on the FW1 side.
Reply With Quote
  #4 (permalink)  
Old 2006-03-25
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Spoofing and VPN conflict.

AFAIK Wire mode bypasses all security checks
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0