We are using secureclient. I would like to change this on the clienbt side is at all possible... I attached the userc file code.
(
:options (
:predefined_profiles_only (false)
:predefined_sites_only (false)
:enable_log_collection (true)
:default_key_scheme (isakmp)
:connect_mode_erase_pwd_after_update (true)
:active_resolver (true)
:resolver_ttl (0)
:resolver_session_interval (0)
:silent_topo_update (false)
:use_entelligence (false)
:manual_slan_control (true)
:user_manual_gui_control (true)
:user_manual_cli_control (true)
:encrypt_db (false)
:gettopo_port (264)
:force_udp_encapsulation (false)
:force_sr_route_through_gw (false)
:no_clear_tables (false)
:allow_clear_in_enc_domain (false)
:use_ext_auth_msg (true)
:use_ext_logo_bitmap (true)
:pwd_erase_on_time_change (false)
:enable_kill (true)
:enable_mode_switching (true)
:enable_sounds (true)
:sdl_max_wait (-1)
:ChangeIKEport (true)
:ChangeUDPsport (true)
:topology_over_IKE (true)
:reload_lmhosts_on_topology (false)
:mac_xlate (false)
:mac_xlate_interval (90)
:connect_mode (true)
:allow_clear_traffic_while_disconnected (false)
:block_conns_on_erase_passwords (false)
:disconnect_on_dialup_change (true)
:disable_mode_transition (false)
:connect_domain_logon (false)
:sdl_main_timeout (120000)
:sdl_main_timeout_user (0)
:sdl_main_silent_timeout (false)
:show_disabled_profiles (false)
:silent_update_on_connect (false)
:stop_connect_when_silent_update_fails (false)
:suppress_dialog_when_creds_available (false)
:go_online_days_before_expiry (0)
:go_online_always (false)
:implicit_disconnect_threshold (180)
:connect_api_support (false)
:disconnect_on_IKE_SA_expiry (false)
:suppress_ike_keepalive (false)
:use_ext_logo_bitmap (true)
:active_test (
:0 (
:test_name (ping_loopback)
:test_parameters ()
)
:1 (
:test_name (ping_def_gw)
:test_parameters ()
)
:2 (
:test_name (dttunneltest)
:test_parameters ()
)
)
:sda_implicit (false)
:sda_implicit_frequency (10080)
:disable_split_dns_when_disconnected (true)
:disable_split_dns_in_om (true)
:message_viewer_max_size (10)
:tcpt_settings (no_proxy)
:tcpt_proxy_address ()
:tcpt_proxy_port (0)
:tcpt_proxy_username ()
:tcpt_proxy_password ()
:ie_proxy_replacement (true)
:ie_proxy_replacement_limit_to_tcpt (true)
:pmtu_max (1350)
:open_full_diagnostic_tool (false)
:fail_connect_on_tt_failure (false)
:tt_failure_show_notification (false)
:simplified_client (true)
:simplified_client_route_all_traffic (false)
:simplified_client_terminate_on_invalid_params (true)
:disable_icf_on_connect (manual)
:api_manual_slan_control (false)
:disconnect_when_in_enc_domain (true)
:suppress_all_balloons (false)
:allow_to_change_3rd_party_auth_type (false)
:support_rsa_soft_tokens (true)
:hotspot_enabled (true)
:hotspot (
:enabled (false)
:log (false)
:connect_timeout (600)
:max_ip_count (5)
:local_subnets (false)
:ports (
: (80)
: (443)
: (8080)
)
:block_hotspot_after_connect (false)
:max_trials (0)
)
:disable_split_dns_upon_disable_site (true)
:active_connection_method_detection (true)
:desktop_policy_control (
:extended_control (false)
:smartdefense_enabled (false)
:scv_dynamic_updates_enabled (false)
:smartdefense_manual_control (true)
:scv_manual_control (true)
)
:user_language (0)
:user_language_manual_control (true)
:prompt_for_no_suitable_profile (true)
:slan_enabled (true)
:global_force_udp_encapsulation (false)
:global_support_tcp_ike (true)
:global_support_tcpt (false)
:global_sr_route_through_gw (false)
:support_tcp_ike (false)
:support_tcpt (true)
:sr_route_through_gw (false)
:support_ip_assignment (true)
)
:gws (
: ("Sarasota CU.sccufw"
:obj (
: (209.241.228.60)
)
:keymanager (
:type (refobj)
:refname ("#_Sarasota CU")
)
:ifaddrs (
: (209.241.228.60)
: (192.168.76.103)
: (192.168.2.1)
)
:topology (
: (
:name ("Sarasota CU.sccufw.0.0")
:type (network)
:ipaddr (10.0.0.0)
:ipmask (255.0.0.0)
)
: (
:name ("Sarasota CU.sccufw.1.0")
:type (network)
:ipaddr (192.168.2.0)
:ipmask (255.255.255.0)
)
: (
:name ("Sarasota CU.sccufw.2.0")
:type (network)
:ipaddr (192.168.76.0)
:ipmask (255.255.255.0)
)
: (
:name ("Sarasota CU.sccufw.3.0")
:type (network)
:ipaddr (192.168.90.0)
:ipmask (255.255.255.0)
)
: (
:name ("Sarasota CU.sccufw.3.1")
:type (network)
:ipaddr (192.168.78.0)
:ipmask (255.255.254.0)
)
: (
:name ("Sarasota CU.sccufw.3.2")
:type (network)
:ipaddr (192.168.88.0)
:ipmask (255.255.254.0)
)
: (
:name ("Sarasota CU.sccufw.3.3")
:type (network)
:ipaddr (192.168.80.0)
:ipmask (255.255.248.0)
)
: (
:name ("Sarasota CU.sccufw.4.0")
:type (network)
:ipaddr (192.168.255.252)
:ipmask (255.255.255.252)
)
: (
:name ("Sarasota CU.sccufw.5.0")
:type (network)
:ipaddr (209.241.228.60)
:ipmask (255.255.255.255)
)
: (
:name ("Sarasota CU.sccufw.5.1")
:type (network)
:ipaddr (209.241.228.58)
:ipmask (255.255.255.254)
)
)
:fwver (6.0)
:option_pack (8)
:firewall (installed)
:uencapport (2746)
:certificates (
: ("O=gatekeeper..wyngkb"
: ("CN=sccufw VPN Certificate,O=gatekeeper..wyngkb")
)
)
:is_isakmp (true)
:is_subnet_support (true)
:ISAKMP_hybrid_support (true)
:isakmp.ipcomp_support (true)
:supports_tcp_ike (use_site_default)
:keep_DF_flag_SR (false)
:copy_DF_flag_SR (false)
:allowed_interface_ranges (
: (209.241.228.60
:allowed_range (
: (
:type (machines_range)
:ipaddr_first (0.0.0.0)
:ipaddr_last (255.255.255.255)
)
)
:is_ext (true)
:is_natted (false)
)
)
:resolve_interface_ranges (true)
:peers ()
:gw_support_nat_t (true)
)
)
:managers (
: ("Sarasota CU"
:obj (
:type (node)
: (209.241.228.60)
)
:dnsinfo (
:dns_servers (
: (DNS-Server
:obj (
: (192.168.76.160)
)
:domain (
: (
:domain (.sccu.coop)
:dns_label_count (4)
)
: (
:domain (.sccu.org)
:dns_label_count (4)
)
)
:topology ()
)
)
:encrypt_dns (true)
)
:MgmtInternalCA (
:public (
:value (03)
)
:modulus (
:value (cd9e0153d3cbcce945f251918612df550fa7442e0db8a9e0ab114fe225943a07e62e7b925222cb9587229d3e57c5e8d65fa0b0b64ef16ab1edfe0de8a5ab411d52e5f9ddb11871ff594aa2ce0da2d22e716fa456328e1e1b409bf26bc78a74d31befa283be15d7430d0466630e9af11a5ab5695c9a6738c00fac1ced197d0e27806f681c1a79c560b8d1c6d9fc06c4faf411eb48e68c9a0e45a98cd5497f73a4cff03cdba7295ac74209985a39a8678c49f9a8734f72ab939fbded0e70e6404454adde6ca80b9a8ce23f1c409d124e4d2cb2be6a9392fe6b107ab7ec4993048260b538a9d24292c43e86168d46160544afa240d3280d598a0365c740c5037b1f)
)
:cert (09cc39bf3fce5f89358a255c19a510fc81aa51ca52c5fd616b580f3a9cbfab8e47ded73c61e3f7fc71aa2332e4e1cf06bd736dcfad885915d231f5665744251d6c766422476852dd10f6767b186f74318e2cca9249b35ab10e25e8653886433614979a56f4dc5a9a4eb9330f68176356b728ede918967057b465ecc995228c2586f96b90aed9cccba551d186f81c88dea971122a21a74963b612307e7360a4efbb9a6d653e50849b0bff1d4c68458dfc4f2bbf152e50eb82e201b84434afa6a72a556e4708b9171da851f68089496edce8c581d01a74dc48bda5809ecb7de33ad126c5c97e603ccde620287a2f2dbec289765b09d67cd134005623dacb80d14c000101820300050501010df78648862a09060d308601020304040001010f1d5503060e30ff010103300504ff0101131d5503060f30213023a30301021f7b03c540c765038a590d28d340a2af440516468d16863ec49242d2a938b56082049349ecb77a106bfe92936abeb22c4d4e129d401c3fe28c9a0ba86cdead544440e6700eedbd9f93ab724f73a8f9498c67a8395a980942c75a29a7db3cf0cfa4737f49d58ca9450e9a8ce648eb11f4fac406fcd9c6d1b860c5791a1c686f80270e7d19ed1cac0fc038679a5c69b55a1af19a0e6366040d43d715be83a2ef1bd3748ac76bf29b401b1e8e3256a46f712ed2a20dcea24a59ff7118b1ddf9e5521d41aba5e80dfeedb16af14eb6b0a05fd6e8c5573e9d228795cb2252927b2ee6073a9425e24f11abe0a9b80d2e44a70f55df12869151f245e9cccbd353019ecd000101820208018230000d01820300050101010df78648862a09060d3020018230626b676e79772e2e72657065656b6574616712130a0455030619301b311d305a3631333232323732313036320d175a3631333232323130323036300d171e30626b676e79772e2e72657065656b6574616712130a0455030619301b311d3000050501010df78648862a09060d3001010202010203a0be018230d6028230)
:dn ("O=gatekeeper..wyngkb")
:date (43e28667)
)
:last_auth_method (hybrid-ike)
:date (49b66266)
:disable (false)
:disconnect_on_token_removal (false)
:to_expire (false)
:expire (120)
:cache_passwords (false)
:update_topo_at_start (false)
:policy_expire (60)
:crl_start_grace (5400)
:crl_end_grace (5400)
:sr_dont_check_crl (false)
:PS_HA (true)
:PS_LB (false)
:keep_alive (true)
:keep_alive_interval (20)
:silent_topo_update (true)
:site_default_tcp_ike (true)
:topology_over_IKE (true)
:ike_negotiation_timeout (36)
:phase2_proposal (large)
:phase2_proposal_size (small)
:phase2_aes_key_size (128)
:vpn_peer_ls (false)
:ike_support_dos_protection (true)
:ike_dos_protection (puzzles)
:ike_dos_acceptable_puzzle_level (19)
:ike_dos_max_puzzle_time (5000)
:enable_automatic_policy_update (false)
:silent_policy_update (false)
:automatic_policy_update_frequency (10080)
:skip_automatic_policy_update_if_authentication_required (true)
:renew_users_ica_cert (true)
:upgrade_fp1_and_below_users_ica_cert (true)
:renew_users_ica_cert_days_before (60)
:sda_implicit (false)
:sda_implicit_frequency (10080)
:allow_clear_traffic_while_disconnected (true)
:send_clear_traffic_between_encryption_domains (false)
:post_connect_script_show_window (false)
:trust_all_capi_cas (false)
:ie_proxy_replacement (false)
:ie_proxy_replacement_limit_to_tcpt (true)
:user_certs_key_size (1024)
:update_frequency (604800)
:phase1_dhgrp ("Group 2 (1024 bit)"
:DH_group_number (2)
:mod (
:value (ffffffffffffffffc90fdaa22168c234c4c6628b80dc1cd129024e088a67cc74020bbea63b139b22514a08798e3404ddef9519b3cd3a431b302b0a6df25f14374fe1356d6d51c245e485b576625e7ec6f44c42e9a637ed6b0bff5cb6f406b7edee386bfb5a899fa5ae9f24117c4b1fe649286651ece65381ffffffffffffffff)
)
:modsize (1024)
:private_key_length (192)
:root (
:value (02)
)
:rootsize (2)
:type (IKE_DH_parameters)
)
:management_ver (
:option_pack (8)
:cpver (6.0)
)
:active_test (
:0 (
:test_name (ping_loopback)
:test_parameters ()
)
:1 (
:test_name (ping_def_gw)
:test_parameters ()
)
:2 (
:test_name (dttunneltest)
:test_parameters ()
)
)
:silent_update_on_connect (false)
:stop_connect_when_silent_update_fails (false)
:single_om_per_site (false)
:enable_log_collection (true)
:disconnect_when_in_enc_domain (true)
:hotspot (
:ports (
: (443)
: (80)
: (8080)
)
:block_hotspot_after_connect (false)
:connect_timeout (600)
:enabled (false)
:is_dirty (true)
:local_subnets (false)
:log (false)
:max_ip_count (5)
:max_trials (0)
)
:idleness_detection (
:active (false)
:excluded_services ()
:timeout (30)
)
:use_profile_ps_configuration (false)
:simplified_client_route_all_traffic (false)
:disable_MEP (false)
:scv_allow_sr_clients (false)
:cache_password (false)
:use_cert (false)
:pwd_type (true)
:certfile_need_pin (false)
:auth_type (0)
:securid_type (0)
:last_used_gw (sccufw)
:should_have_ike_sa_on_connect (false)
:download_topo_from_ip (0xd1f1e43c)
:partial_topo (false)
)
)
:policy_servers ()
:sds_servers ()
:profiles (
:active_profile ("Sarasota CU")
:active_gw (sccufw)
: ("Sarasota CU"
:attributes (
:read_only (false)
:description ("Sarasota CU default profile")
)
:options (
:support_tcp_ike (false)
:force_udp_encapsulation (false)
:support_tcpt (true)
:support_ip_assignment (true)
:sr_route_through_gw (false)
:ps_ha_scheme (ps_pool)
)
:gateways (
: ("Sarasota CU.sccufw"
:name ("Sarasota CU.sccufw")
:ipaddr (209.241.228.60)
:active (true)
)
)
:policy_servers ()
:site ("Sarasota CU")
:active_gw (sccufw)
)
)
)
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: 231: 232: 233: 234: 235: 236: 237: 238: 239: 240: 241: 242: 243: 244: 245: 246: 247: 248: 249: 250: 251: 252: 253: 254: 255: 256: 257: 258: 259: 260: 261: 262: 263: 264: 265: 266: 267: 268: 269: 270: 271: 272: 273: 274: 275: 276: 277: 278: 279: 280: 281: 282: 283: 284: 285: 286: 287: 288: 289: 290: 291: 292: 293: 294: 295: 296: 297: 298: 299: 300: 301: 302: 303: 304: 305: 306: 307: 308: 309: 310: 311: 312: 313: 314: 315: 316: 317: 318: 319: 320: 321: 322: 323: 324: 325: 326: 327: 328: 329: 330: 331: 332: 333: 334: 335: 336: 337: 338: 339: 340: 341: 342: 343: 344: 345: 346: 347: 348: 349: 350: 351: 352: 353: 354: 355: 356: 357: 358: 359: 360: 361: 362: 363: 364: 365: 366: 367: 368: 369: 370: 371: 372: 373: 374: 375: 376: 377: 378: 379: 380: 381: 382: 383: 384: 385: 386: 387: 388: 389: 390: 391: 392: 393: 394: 395: 396: 397: 398: 399: 400: 401: 402: 403: 404: 405: 406: 407: 408: 409: 410: 411: 412: 413: 414: 415: 416: 417: 418: 419: 420: 421: 422: 423: 424: 425: 426:





by: deimarkPosted on 2009-03-11 at 02:25:03ID: 23855033
In short, split tunnelling can be set on either the client or the main firewall you connect to.
Can you confirm how you connect to the firewall? Is it via secureremote or secureclient? (these are Check Point VPN clients made for connecting to remote access VPNs on Check Point firewalls.
If yes, then there will be a userc.C file on the client machine, can you please upload a copy here for us to look at?