CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-21
Junior Member
 
Join Date: 2006-01-04
Posts: 7
Rep Power: 0
elad_ has an average reputation (10+)
Default VPN Domain

Hi All

I have a VPN problem and I wondering if anyone can help me with that:
I have setup a SITE to SITE VPN and I have also a remote access VPN to both sites.
I’ve tried to add some networks from 1 site to the other site VPN domain and it didn’t work
It mess up my site to site VPN
Is there any way I can do this ?

Thanks,
Elad
Reply With Quote
  #2 (permalink)  
Old 2006-02-22
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: VPN Domain

There are two ways you could do this. Either have one site in the Remote Access group and route traffic through the one site across the SITE-SITE tunnel, or put both sites into the Remote Access group.

Both sites in the Remote Access group:
The VPN Domain for each site should only include networks that live behind the site. Secure client will authenticate to each site as needed (IE if you authenticate to the first site, and try to access a resource in the second site, you'll receive another authentication prompt).

One site in the Remote Access group:
The site in the Remote Access group should have a VPN Domain that includes networks for both sites. The second site that is not in the Remote Access group should have it's normal VPN domain defined. The trick to making this work is to create VPN Routing entries for the second site on the first site's firewall (edit $FWDIR/conf/vpn_route.conf on the Management Server). Here's an example of VPN_route:
# Enable encryption for SecureClient -> Second Site:
EncryptionDomainFW2 FW2 FW1 force_override

Another way to do the "One site in the Remote Access group" is to use "Hub Mode" for your Remote Access group. This is actually specified in Manage -> Remote Access -> Connection Profiles -> Advanced. In this case the VPN Domain for each site should only include networks that live behind that firewall. Hub Mode means that all your internet traffic will route through the firewall [not just traffic destined for hosts in the VPN Domain].

HTH

Last edited by melipla; 2006-02-22 at 10:31. Reason: clarification
Reply With Quote
  #3 (permalink)  
Old 2006-02-22
Junior Member
 
Join Date: 2006-01-04
Posts: 7
Rep Power: 0
elad_ has an average reputation (10+)
Default Re: VPN Domain

Thanks i've setup the hub mode and it's working
but i don't understand you second solution
Reply With Quote
  #4 (permalink)  
Old 2006-02-28
Junior Member
 
Join Date: 2006-02-28
Posts: 17
Rep Power: 0
stefan73er has an average reputation (10+)
Default Re: VPN Domain

Hi,

i have also a problem that is similar to this with only some differences.

current situation:
1 Checkpoint GW NG R55 config in traditional mode (vpn dom is network1)
1 Cisco IPsec router setup as interoperable device in CP (VPN Dom is network2)
network1 is behind the checkpoint
network2 is behind the cisco
between both networks i have a VPN tunnel
Remote users have SecuRemote installed and connect to the Checkpoint


The remote users can access the network1 but not network2 because its not in the vpn domain of the Checkpoint.

Is there also a solution for this?

How do i configure the Connection Profile with HubMode? I can create one but don´t know what to do with it after creation. Do i have to bound it to something or is it automaticly active then. If so for who is it active?

Thanks in advance for your help!

best regards

Stefan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:31.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0