sk25494 Derek O'Flynn
-----Original Message----- From: Ray Pesek [mailto:[EMAIL PROTECTED] Sent: Tuesday, June 08, 2004 12:50 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en cryption domain Sorry, old timer's disease has set in again. What was that article number I gave you? >From: "O'Flynn, Derek" <[EMAIL PROTECTED]> >Reply-To: Mailing list for discussion of Firewall-1 ><[EMAIL PROTECTED]> >To: [EMAIL PROTECTED] >Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en >cryption domain >Date: Tue, 8 Jun 2004 10:35:02 -0500 > >I keep escalating it through CheckPoint, I'm up to one of their senior >bench >guys. From what I can tell they are unsure why it's occurring. I did talk >to another end user at CP Experience, and they experienced the same thing >on >XP. In addition I also spoke to CP's VPN lead and VP of products at this >week and they were curious as well. They thought it might be a state >issue, >since WINS is hard coded as soon as the machine comes online it may have a >previous state entered before I connect to the VPN. Once connected it >continues to pass the traffic in clear per the previous state. Once this >times out then it creates a new state which redirects it through the >tunnel. >I also couldn't find the SK article you mentioned on secure track. I keyed >it in, but it couldn't find results. Do you have the HREF handy? > >Derek O'Flynn >Enterprise Information Security >LSU Health Sciences Center >[EMAIL PROTECTED] (504)568-6130 > >-----Original Message----- >From: Ray Pesek [mailto:[EMAIL PROTECTED] >Sent: Monday, June 07, 2004 8:09 PM >To: [EMAIL PROTECTED] >Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en >cryption domain > >Thanks, Derek. That's pretty much the way it's working. We took great pains >on both ends to assure that only this one IP on each end could be accessed >via the VPN, so including the web server in the VPN opens a whole host of >other issues. We don't need HTTP over the VPN, so it looks like the best >interim solution is to just exclude the HTTP service. > >This certainly is a pain, though. If there is no access allowed in the "if >via" rule, then it shouldn't matter. In my opinion, anyway. :-) Or let me >define the encryption domain on my side for each VPN community. That would >be very nice! > >We do need the web server in the encryption domain for other site-to-site >VPNs we're planning. > >BTW, did you get anywhere on your WINS issue? > >Take care, > >Ray > > > >From: "O'Flynn, Derek" <[EMAIL PROTECTED]> > >Reply-To: Mailing list for discussion of Firewall-1 > ><[EMAIL PROTECTED]> > >To: [EMAIL PROTECTED] > >Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site >en > >cryption domain > >Date: Mon, 7 Jun 2004 17:56:10 -0500 > > > >We have had a similar issue. > > > >We have a site to site VPN setup with an external site. > > > >Servers needing access are defined on the if via rule. > > > >Encryption domain on our side includes subnets at my site. > > > >The difference lies, in that the web server we try to get to is on the > >external site's network. > > > >We could not get to their website. I believe the packet was dropped. > >Reason was that the website was included in the encryption domain of the > >external site and CheckPoint would include it in the VPN rule and this >site > >did not have access via the rule and would get dropped. > > > >We found out that we had defined the encryption domain for the external > >site > >incorrectly. Once we corrected this, they were able to access the >website. > > > >So I believe that if your webservers are included in your encryption >domain > >you will see the same issue. It is possible that you could create a > >network > >object with your defined subnets for the encryption domain, and then use >a > >negate group to negate the web server from the encryption domain, and >apply > >this to the topology. But of course this has other issues...where you >need > >the web server as part of the encryption domain. > > > >Another thing you could try is include this webserver as part of the site > >to > >site VPN with the other site, then instead of them coming cleartext to >the > >site, they would come through the VPN. > > > >Derek O'Flynn > >Enterprise Information Security > >LSU Health Sciences Center > >[EMAIL PROTECTED] (504)568-6130 > > > >-----Original Message----- > >From: Ray Pesek [mailto:[EMAIL PROTECTED] > >Sent: Monday, June 07, 2004 1:33 PM > >To: [EMAIL PROTECTED] > >Subject: [FW-1] Remote Access encryption domain versus site-to-site > >encryption domain > > > >We have our entire internal network defined as being in the encryption > >domain for remote access use. > > > >We also have a frame connection to a partner that terminates on a server >in > >the encryption domain. We want to replace it with a site-to-site >Simplified > >VPN. They're running a WatchGuard 7.0 Firebox III system. > > > >We got the VPN up and running OK but we have one oddity. We also have a >web > >server on our internal network (in the encryption domain) that is > >accessible > >from certain IP addresses on the Internet. It is also used by this >partner. > > > >When the partner tries to access the web server from the Internet, the > >connection is dropped as a cleartext packet in an encrypted connection. >If > >I > >exclude HTTP from the Simplified Community, it works OK. > > > >It appears that the Remote Access and Site-to-Site encryption domains > >cannot > >be separated at all even though the rule that has the "if via" objects in > >Source and Destination only specifiy a particular IP address. > > > >I was thinking that if the "if via" rule did not specify the IP address >of > >the web server, and it doesn't, then traffic to the web server would not > >have to go down the tunnel as well. The VPN server and the web server are > >only one digit different in IP addresses, if that matters. > > > >Can anyone shed some light on whether this behavior is correct? That if > >traffic originates from a Simplified VPN satellite gateway, then all > >traffic > >to any IP contained in the encryption domain must be encrypted even if >the > >rule base does not specify this? R55, by the way. > > > >Thanks, > > > >Ray > > > >_________________________________________________________________ > >Check out the coupons and bargains on MSN Offers! >http://youroffers.msn.com > > > >================================================= > >To set vacation, Out-Of-Office, or away messages, > >send an email to [EMAIL PROTECTED] > >in the BODY of the email add: > >set fw-1-mailinglist nomail > >================================================= > >To unsubscribe from this mailing list, > >please see the instructions at > >http://www.checkpoint.com/services/mailing.html > >================================================= > >If you have any questions on how to change your > >subscription options, email > >[EMAIL PROTECTED] > >================================================= > > > >================================================= > >To set vacation, Out-Of-Office, or away messages, > >send an email to [EMAIL PROTECTED] > >in the BODY of the email add: > >set fw-1-mailinglist nomail > >================================================= > >To unsubscribe from this mailing list, > >please see the instructions at > >http://www.checkpoint.com/services/mailing.html > >================================================= > >If you have any questions on how to change your > >subscription options, email > >[EMAIL PROTECTED] > >================================================= > >_________________________________________________________________ >Stop worrying about overloading your inbox - get MSN Hotmail Extra Storage! >http://join.msn.click-url.com/go/onm00200362ave/direct/01/ > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= > >================================================= >To set vacation, Out-Of-Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= _________________________________________________________________ FREE pop-up blocking with the new MSN Toolbar - get it now! http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/ ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
