[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

06/24/2009 at 08:54AM PDT, ID: 24518654
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

6.8

Checkpoint VPN - Secureclient connection issues, can't connect to internal LAN. NGX R65 UTM-1 270

Asked by evollic in Checkpoint Firewall, Enterprise Firewalls, Virtual Private Networking (VPN)

Tags: Checkpoint VPN, secureclient, ngx r65

Ok so here's the issue. I have a UTM-1 270 NGX R65 with VPN turned on. I am using the certificate method for authentication with the latest Secureclient installed (ver. NGX R60 HFA2 Build 002). A remote user can connect to the VPN using the Secureclient, get authenticated and successfully connected and assigned an IP through the IP Pool I have setup, also they get the dns servers I have them pointed to, but they can't access the internal LAN to get to our Exchange server and file servers, nor does their internet access work after connected.

Here is how I have my network/objects setup in the Checkpoint:
- Firewall: Checkpoint UTM-1 270 NGX R65, internal IP: 10.0.0.3 Ext. IP x.x.x.251
- Internal Lan 10.0.0.0/22 (10.0.0.0-10.0.3.254 for those that are lazy...) Auto Nat rules are inplace w/ matching security rules.
- IP Pool for VPN users 10.0.4.0/24 (10.0.4.0-10.0.4.254 again for those that are lazy...). Also I have IP pool with NO Nat setup.
- Security rule allowing any to any with VPN traffic for "remote access" being accepted.
- "Remote Access" setup for VPN with VPN user group (with all correct users inside group)
- Office Mode is enabled with users being given an IP from the Pool above. Hub mode is also enabled.
- IP spoofing is turned on with VPN IP Pool selected.
- DNS servers are assigned to the VPN users and are set as our local DNS servers
- Secureclients are set for Officemode and hub mode.

Once connected with Secureclient I can see the logs showing correct authentication with encrypted/decrypted packets being allowed. On the Secureclient side I see the user get assigned an IP from the IP pool and dns servers set. The Secureclient log shows deny and gives the error "Packet is from physical IP address but office mode is enabled". I have tried this from internally and remotely and I get the same issue. My traffic is blocked to any internal LAN so even if I try to ping a local server I get "can't find" etc. Any ideas?
[+][-]06/24/09 09:31 AM, ID: 24702788

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06/24/09 09:57 AM, ID: 24703034

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/05/09 10:54 PM, ID: 24782873

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/06/09 12:33 AM, ID: 24783219

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/06/09 01:34 AM, ID: 24783423

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/06/09 01:37 AM, ID: 24783437

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07/09/09 06:39 AM, ID: 24813461

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/20/09 12:10 PM, ID: 24897980

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07/21/09 12:35 AM, ID: 24901924

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]08/24/09 08:45 AM, ID: 25169484

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Checkpoint Firewall, Enterprise Firewalls, Virtual Private Networking (VPN)
Tags: Checkpoint VPN, secureclient, ngx r65
Sign Up Now!
Solution Provided By: evollic
Participating Experts: 2
Solution Grade: A
 
 
[+][-]08/29/09 04:44 AM, ID: 25213772

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-91 - Hierarchy / EE_QW_3_20080625