CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-24
Junior Member
 
Join Date: 2005-09-30
Posts: 12
Rep Power: 0
suzy_reid has an average reputation (10+)
Default Port 500 - not listening

Hi

I'm having problems with users conencting via Securemote - in the fw logs they come in on port 500 - but then nothing happens. On the client side they get a "gateway not responding message"

I ran netstat -an to check that the firewall is listening on Port 500 - but it isn't! What can I do to get this working again??
thanks
Reply With Quote
  #2 (permalink)  
Old 2006-04-24
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Port 500 - not listening

May be you need to restart vpnd (vpn drv off/on) or/and debug it (vpn debug on/off).
Reply With Quote
  #3 (permalink)  
Old 2006-04-24
Junior Member
 
Join Date: 2005-09-30
Posts: 12
Rep Power: 0
suzy_reid has an average reputation (10+)
Default Re: Port 500 - not listening

ok

If I do VPN DRV on - it says it is working okay.
But if I attempt to do a VPN debug I get an error "cannot find PID of VPND". The PID file is there with a few numbers in it???

The firewall will listen on port 500 if I enable IPSec as a windows service - but if I disable this service as per Checkpoint instructions no listening is taking place....

thanks
Reply With Quote
  #4 (permalink)  
Old 2006-04-25
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Port 500 - not listening

Do you use Windows platform?

I try commands (vpn drv off/on) on my module - it's "bad" commands :) After vpn drv off/on, i have error like yours.

Execute cprestart after that vpn debug on and check log (vpnd.elg), also see "event viewer". May be some CP services didn't start and windows log has information about errors.
Reply With Quote
  #5 (permalink)  
Old 2006-04-26
Junior Member
 
Join Date: 2005-09-30
Posts: 12
Rep Power: 0
suzy_reid has an average reputation (10+)
Default Re: Port 500 - not listening

hi, thanks for the advice so far.
All the services are starting ok. If we try and do a "VPN VPND" we get
"cannot signal vpnd".

We get no encrypted traffic at all logged - though we can see clients coming in with accepted IKE traffic on port 500 when they try and link via Securemote - but nothing happens.
Is there an easy way to reinstall VPN-1 Pro??
Reply With Quote
  #6 (permalink)  
Old 2006-04-27
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Port 500 - not listening

If all log is empty and you don't have another obstacles, why not. Really, may be problem with corrupted installation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:52.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0