CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2009-11-24
Junior Member
 
Join Date: 2007-11-28
Posts: 6
Rep Power: 0
dub_boy2k has an average reputation (10+)
Default Cert based VPN

Guys,

I'm having a major issue with cert based VPN's.

I have two firewall clusters in seperate countries, all managed by one mgt server.

I'm getting a invalid cert message log on the remote VPN. The modules are SIC and policy can be pushed. The VPN rule is setup correctly

In relation to this,

Can someone provide me with steps to make this work so I'll hopefully I'll find out where I'm going wrong.
Reply With Quote
  #2 (permalink)  
Old 2009-11-24
Senior Member
 
Join Date: 2006-12-16
Posts: 477
Rep Power: 4
Routerkid1 has an average reputation (10+)
Default Re: Cert based VPN

I would reset sic.
Reply With Quote
  #3 (permalink)  
Old 2009-11-24
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 697
Rep Power: 2
msjouw has an average reputation (10+)
Default Re: Cert based VPN

Double check routing from the local gateway back to the management server (SCS), did you recently change anything there regarding routing, specially about 3-5 days ago?

Sounds like a similar issue I had with asymmetric routing, the gateways were managed from the external IP but the route to the management server was pointing to the internal network (in our environment this is possible).

The local gateway will try to connect to the SCS and when the connection is made from any other IP than the gateway object's IP it will not accept the connection on the SCS. The cache on the local gateway is somewhere between 3-5 days.

There is a specific port it uses to check the certs with the SCS and I don't know anymore which one it is. You could run a tcpdump looking for this port on the SCS.

Do keep in mind that when the SCS initiates traffic to the gateway it will be ok.
__________________
Regards, Maarten.
P1 R65.4 IPSO SPLAT IOS
Reply With Quote
  #4 (permalink)  
Old 2009-11-26
Junior Member
 
Join Date: 2007-11-28
Posts: 6
Rep Power: 0
dub_boy2k has an average reputation (10+)
Default Re: Cert based VPN

Lads

Solution was to NAT the mgt server with the private IP addres behind a pubic IP.

Create a dummy checkpoint node, set up as secondary mgt server, create the correct NAT rules and bobsyour uncle and fannys your aunt

Thanks

dub
Reply With Quote
Reply

Tags
certificate, vpn

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:21.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1