Re: Checkpoint NG AI VPN gatewa behind NAT

From: Drx (read_at_from.sign)
Date: 08/16/05

  • Next message: Nicky: "Re: Penetration test requested!"
    Date: Tue, 16 Aug 2005 08:13:52 +0200
    
    

    On Mon, 15 Aug 2005 19:30:48 GMT, Memnoch wrote:

    > On Mon, 15 Aug 2005 13:15:56 +0200, no@no.no wrote:
    >
    >>m VPN gatewa is behind NAT and I cannot make SmartClient VPN connection. Is
    >>there any cookbook how to configure Checkpoint for this?
    >
    > You will need to forward all ports on the machine doing NAT to the gateway
    > related to SecurClient/SecureRemote.
    >
    > From their KB:
    >
    > If there are other firewalls along the path connecting the SecuRemote Client
    > (that performs the encryption) and the VPN-1/FireWall-1 Server (the
    > VPN-1/FireWall-1 Module that performs the decryption), configure the other
    > firewalls to allow FW-1 services to pass from the SecuRemote Client to the
    > SecuRemote Server.
    >
    > Allow the following services:
    >
    > TCP/264 (Topology Download)
    > IKE
    > IPSEC and IKE (UDP on port 500)
    > IPSEC ESP (IP type 50)
    > IPSEC AH (IP type 51)
    > TCP/500 (if using IKE over TCP)
    > UDP 2746 or another port (if using UDP encapsulation)
    >
    > SecureClient specific connections:
    >
    > FW1_scv_keep_alive (UDP port 18233) — used for SCV keep-alive packets
    > FW1_pslogon_NG (TCP port 18231) or (TCP port 65524 for Application
    > Intelligence) — used for SecureClient's logon to Policy Server protocol
    > FW1_sds_logon (TCP port 18232) — used for SecureClient's Software Distribution
    > Server download protocol
    > tunnel_test (UDP port 18234) - used by Check Point tunnel testing application

    abd how to solve source address that checkpoint use for packets. It uses
    private IP address


  • Next message: Nicky: "Re: Penetration test requested!"

    Relevant Pages

    • Re: Processs PreciseMail AntiSpam Gateway - any experience so far ?
      ... Client sending system ... >> ISP using dynamic NAT with port overloading. ... >> 10.11.12.1 is the clients real address and it opens a connection from its port ...
      (comp.os.vms)
    • Re: WinRoute Pro
      ... If a RST is sent to a TCP protocol host, ... 1/ Check the NAT table. ... 2/ Open a TCP connection to a host using a port tool. ... Winroute's logs are no substitute for a decent packet sniffer. ...
      (comp.security.firewalls)
    • Re: Establish external trust over a NAT device
      ... suggesting hardware over Windows built-in functionality for a VPN solution. ... even a fairly cheap router will likely have much better throughput ... L2TP and routing over it with or without NAT on that connection. ...
      (microsoft.public.win2000.active_directory)
    • Re: NAT and keepaliveopen connection over TCP
      ... sent after 10 minutes of inactivity on the TCP connection. ... There's no minimum set time how long a NAT router should ... time-out inactive connections at the server. ...
      (microsoft.public.win32.programmer.networks)
    • Re: Microsoft Worm
      ... > securing their machines and who require full access to the internet. ... > every provider imposed NAT on their customers and started blocking ports, ... As for NAT, I've always had a NAT system on my home internet connection ...
      (alt.computer.security)

    Loading