I keep escalating it through CheckPoint, I'm up to one of their senior bench
guys.  From what I can tell they are unsure why it's occurring.  I did talk
to another end user at CP Experience, and they experienced the same thing on
XP.  In addition I also spoke to CP's VPN lead and VP of products at this
week and they were curious as well.  They thought it might be a state issue,
since WINS is hard coded as soon as the machine comes online it may have a
previous state entered before I connect to the VPN.  Once connected it
continues to pass the traffic in clear per the previous state.  Once this
times out then it creates a new state which redirects it through the tunnel.
I also couldn't find the SK article you mentioned on secure track.  I keyed
it in, but it couldn't find results.  Do you have the HREF handy?

Derek O'Flynn
Enterprise Information Security
LSU Health Sciences Center
[EMAIL PROTECTED] (504)568-6130

-----Original Message-----
From: Ray Pesek [mailto:[EMAIL PROTECTED]
Sent: Monday, June 07, 2004 8:09 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en
cryption domain

Thanks, Derek. That's pretty much the way it's working. We took great pains
on both ends to assure that only this one IP on each end could be accessed
via the VPN, so including the web server in the VPN opens a whole host of
other issues. We don't need HTTP over the VPN, so it looks like the best
interim solution is to just exclude the HTTP service.

This certainly is a pain, though. If there is no access allowed in the "if
via" rule, then it shouldn't matter. In my opinion, anyway.  :-) Or let me
define the encryption domain on my side for each VPN community. That would
be very nice!

We do need the web server in the encryption domain for other site-to-site
VPNs we're planning.

BTW, did you get anywhere on your WINS issue?

Take care,

Ray


>From: "O'Flynn, Derek" <[EMAIL PROTECTED]>
>Reply-To: Mailing list for discussion of Firewall-1
><[EMAIL PROTECTED]>
>To: [EMAIL PROTECTED]
>Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en
>cryption domain
>Date: Mon, 7 Jun 2004 17:56:10 -0500
>
>We have had a similar issue.
>
>We have a site to site VPN setup with an external site.
>
>Servers needing access are defined on the if via rule.
>
>Encryption domain on our side includes subnets at my site.
>
>The difference lies, in that the web server we try to get to is on the
>external site's network.
>
>We could not get to their website.  I believe the packet was dropped.
>Reason was that the website was included in the encryption domain of the
>external site and CheckPoint would include it in the VPN rule and this site
>did not have access via the rule and would get dropped.
>
>We found out that we had defined the encryption domain for the external
>site
>incorrectly.  Once we corrected this, they were able to access the website.
>
>So I believe that if your webservers are included in your encryption domain
>you will see the same issue.  It is possible that you could create a
>network
>object with your defined subnets for the encryption domain, and then use a
>negate group to negate the web server from the encryption domain, and apply
>this to the topology.  But of course this has other issues...where you need
>the web server as part of the encryption domain.
>
>Another thing you could try is include this webserver as part of the site
>to
>site VPN with the other site, then instead of them coming cleartext to the
>site, they would come through the VPN.
>
>Derek O'Flynn
>Enterprise Information Security
>LSU Health Sciences Center
>[EMAIL PROTECTED] (504)568-6130
>
>-----Original Message-----
>From: Ray Pesek [mailto:[EMAIL PROTECTED]
>Sent: Monday, June 07, 2004 1:33 PM
>To: [EMAIL PROTECTED]
>Subject: [FW-1] Remote Access encryption domain versus site-to-site
>encryption domain
>
>We have our entire internal network defined as being in the encryption
>domain for remote access use.
>
>We also have a frame connection to a partner that terminates on a server in
>the encryption domain. We want to replace it with a site-to-site Simplified
>VPN. They're running a WatchGuard 7.0 Firebox III system.
>
>We got the VPN up and running OK but we have one oddity. We also have a web
>server on our internal network (in the encryption domain) that is
>accessible
>from certain IP addresses on the Internet. It is also used by this partner.
>
>When the partner tries to access the web server from the Internet, the
>connection is dropped as a cleartext packet in an encrypted connection. If
>I
>exclude HTTP from the Simplified Community, it works OK.
>
>It appears that the Remote Access and Site-to-Site encryption domains
>cannot
>be separated at all even though the rule that has the "if via" objects in
>Source and Destination only specifiy a particular IP address.
>
>I was thinking that if the "if via" rule did not specify the IP address of
>the web server, and it doesn't, then traffic to the web server would not
>have to go down the tunnel as well. The VPN server and the web server are
>only one digit different in IP addresses, if that matters.
>
>Can anyone shed some light on whether this behavior is correct? That if
>traffic originates from a Simplified VPN satellite gateway, then all
>traffic
>to any IP contained in the encryption domain must be encrypted even if the
>rule base does not specify this? R55, by the way.
>
>Thanks,
>
>Ray
>
>_________________________________________________________________
>Check out the coupons and bargains on MSN Offers! http://youroffers.msn.com
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================

_________________________________________________________________
Stop worrying about overloading your inbox - get MSN Hotmail Extra Storage!
http://join.msn.click-url.com/go/onm00200362ave/direct/01/

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to