What exactly does this mean: >I can ping internal_server with the WINS address, nothing happens.
Means that when I attempt "ping server", nothing happens. Means that the WINS request does not resolve the connection, and therefore since it cannot identify the IP, it cannot ping. For instance: Ping server (wins fails, no icmp) Ping server.domain.com (dns succeeds, icmp passes) WINS request are not being redirected through the tunnel for a certain period of time. Usually within 5 minutes this clears up and WINS request work without issue. I'm beginning to wonder if there's some type of state issue with SR. Before I connect because WINS is hardcoded it's continually trying to connect to my WINS servers. Maybe SR is recording a state for WINS. When you connect maybe it believes that this WINS request is to utilize the existing connection which passes the traffic clear instead of redirecting it. Thanks, Derek O'Flynn Enterprise Information Security LSU Health Sciences Center [EMAIL PROTECTED] (504)568-6130 -----Original Message----- From: Ray Pesek [mailto:[EMAIL PROTECTED] Sent: Thursday, June 03, 2004 6:52 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] SecuRemote using WINS, fails to split tunnel Hi Derek, What exactly does this mean: >I can ping internal_server with the WINS address, nothing happens. "can ping" and "nothing happens" seem to be opposite. By "WINS address" I take it you mean the NetBIOS name and not the IP address registered in WINS? I know Windows XP has issues with DNS requests going the wrong way because of their stupid DNS cache and that it can be resolved with R55 and a userc.c mod, but I haven't read anything about WINS having the issue. What OS are the computers on? Even though we're on an NT 4 domain, I always put in a servername.domain.com entry into DNS because 2000 & XP use DNS before they use WINS. Ray >From: "O'Flynn, Derek" <[EMAIL PROTECTED]> >Reply-To: Mailing list for discussion of Firewall-1 ><[EMAIL PROTECTED]> >To: [EMAIL PROTECTED] >Subject: Re: [FW-1] SecuRemote using WINS, fails to split tunnel >Date: Thu, 3 Jun 2004 14:38:26 -0500 > >I'm not utilizing dnsinfo.c for WINS. I'm also not utilizing Office >Mode.(SecuRemote only). I will check the SK and see what it entails. I >thought dnsinfo.c was only utilized during SDL. Can you define the WINS >servers dynamically for SR similar to how SecuRemote DNS works? > >Thanks, > >Derek O'Flynn >Enterprise Information Security >LSU Health Sciences Center >[EMAIL PROTECTED] (504)568-6130 > >-----Original Message----- >From: Ray Pesek [mailto:[EMAIL PROTECTED] >Sent: Thursday, June 03, 2004 6:48 AM >To: [EMAIL PROTECTED] >Subject: Re: [FW-1] SecuRemote using WINS, fails to split tunnel > >Article sk25494 for SecureClient & Office Mode talks about this type of >behavior due to a hard-coded WINS. In your case, it's probably a similar >situation in that the hard-coded WINS is taking precedence over what you >have defined in dnsinfo.c for WINS. > >Ray > > > >From: "O'Flynn, Derek" <[EMAIL PROTECTED]> > >Reply-To: Mailing list for discussion of Firewall-1 > ><[EMAIL PROTECTED]> > >To: [EMAIL PROTECTED] > >Subject: [FW-1] SecuRemote using WINS, fails to split tunnel > >Date: Thu, 3 Jun 2004 00:52:19 -0500 > > > >Scenario: > > > > > > > >I have WINS defined on my local NIC > > > >I am connected to the gateway > > > >I can ping internal_server with the WINS address, nothing happens. > > > >I can ping internal_server.domain.com DNS address, DNS is resolved > >internally, and ICMP proceeds. > > > > > > > >SRFW monitor shows for the WINS address. (passed through normal ISP, not > >through tunnel) > > > >o -> myip -> wins server -> UDP 137 > > > >O -> myip -> wins server -> UDP 137 > > > > > > > >SRFW monitor shows for any other type of connection. (redirected through > >tunnel to gateway) > > > >o -> myip -> server -> otherport > > > >O -> myip -> fwgateway -> UDP 2746 > > > > > > > >After about 3 minutes of it not working, it suddenly starts sending WINS > >request down the tunnel and all is well. During the time it's not >working > >and you perform wins queries, the icon does not move and SRFW shows that > >it's not redirecting it to the tunnel. > > > > > > > >It's seems to be sporadic, but I can get it recreated on multiple >machines. > >It doesn't appear to be a gateway issue. I have tested with R55, and >R56. > >The gateway sees the external request come in but not via the tunnel, but > >via the Internet. It has the error message 'packet passed in clear text > >for > >encrypted connection' and promptly drops it. > > > > > > > >Why for WINS is the request not being redirected through the tunnel? > >Anyone > >seen this? > > > > > > > >Thanks, > > > >Derek > > > > > > > > > >================================================= > >To set vacation, Out-Of-Office, or away messages, > >send an email to [EMAIL PROTECTED] > >in the BODY of the email add: > >set fw-1-mailinglist nomail > >================================================= > >To unsubscribe from this mailing list, > >please see the instructions at > >http://www.checkpoint.com/services/mailing.html > >================================================= > >If you have any questions on how to change your > >subscription options, email > >[EMAIL PROTECTED] > >================================================= > >_________________________________________________________________ >MSN 9 Dial-up Internet Access fights spam and pop-ups - now 3 months FREE! >http://join.msn.click-url.com/go/onm00200361ave/direct/01/ > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= _________________________________________________________________ Looking to buy a house? Get informed with the Home Buying Guide from MSN House & Home. http://coldwellbanker.msn.com/ ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
