Check Point VPN Problem

Posted on 2006-04-06
Last Modified: 2012-06-21
We have in our company Check Point NG FP2 with VPN.
When someone try to connect from outside everything is ok.
Our internal Lan have few subnets (192.168.0.* ,192.168.1.* ,192.168.2.* , 192.168.254.*)

The problem is : When someone on Business travel try to connect from the hotel, the Hotal lan address is usually 192.168.0.* or 192.168.1.* , and on this case it is not possible to connect to the VPN (usually the Checkpoint SecureRemote hangs).

Thanks for any help
Question by:idana2
    LVL 3

    Expert Comment

    check point is operating as it's suppossed to. When the remote user trys to connect with the same lan ip as you lan, it treats it as a spoof attempt to hack your network. i'll see if i can find a work around from checkpoint for you...

    LVL 3

    Accepted Solution

    here is what i found so far...

    Product: SecureClient
    Version: NG AI
    Last Modified: 01-Feb-2006

     Failure to connect with SecureClient to a Security Gateway, when on a network with a private IP range that is also in the VPN Domain
    The SecureClient is located at a remote site, which uses the same IP address range as the internal interface of the Gateway to which the client wishes to connect. The dynamic-resolution feature of SecureClient sees the "closest possible interface" of the remote Gateway as the private IP range address, because the client sees that network as local to the client.
    The suggested and (in most cases) only solution is to use Office Mode. The suggested solution is only helpful when the statically determined Gateway IP address belongs to the remote client's local LAN.

    Configure the Gateway to use "Dynamic interface resolving":

    In SmartDashboard:
    Open Policy > Global Properties > Remote Access.
    Select "VPN Advanced", and change the setting for the resolving mechanism from Static to Dynamic.
    Edit all firewalled objects, and select VPN > VPN Advanced.
    Click "Dynamic interface resolving configuration", and enable option "Enable dynamic resolution for SecuRemote/SecureClient".

    Install the Security Policy. SecureClient users must update the site to get the new information.

    At this point, the clients will resolve the interface with an RDP mechanism, before connecting or choosing the address of the interface to which they wish to connect. This occurs by sending an RDP packet to determine if the address is reachable.  
    Applies To:

    VPN-1/FireWall-1 NG with Application Intelligence R55
    VPN-1 SecureClient NG with Application Intelligence R56
    Dynamic interface resolving
    VPN Domain
    Hotel IP address

    it's tricky, so do a backup before hand, just in case...

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    6 Surprising Benefits of Threat Intelligence

    All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

    Suggested Solutions

    One of the Top 10  common Cisco VPN problems are not-matching shared keys. This is an easy one to fix, but not always easy to notice, see the case below. A simple IPsec tunnel between fast Ethernet interfaces of routers SW1 (f1/1) and R1(f0/0). …
    For a while, I have wanted to connect my HTC Incredible to my corporate network to take advantage of the phone's powerful capabilities. I searched online and came up with varied answers from "it won't work" to super complicated statements that I did…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now