sk25494

Derek O'Flynn

-----Original Message-----
From: Ray Pesek [mailto:[EMAIL PROTECTED]
Sent: Tuesday, June 08, 2004 12:50 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en
cryption domain

Sorry, old timer's disease has set in again. What was that article number I
gave you?


>From: "O'Flynn, Derek" <[EMAIL PROTECTED]>
>Reply-To: Mailing list for discussion of Firewall-1
><[EMAIL PROTECTED]>
>To: [EMAIL PROTECTED]
>Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en
>cryption domain
>Date: Tue, 8 Jun 2004 10:35:02 -0500
>
>I keep escalating it through CheckPoint, I'm up to one of their senior
>bench
>guys.  From what I can tell they are unsure why it's occurring.  I did talk
>to another end user at CP Experience, and they experienced the same thing
>on
>XP.  In addition I also spoke to CP's VPN lead and VP of products at this
>week and they were curious as well.  They thought it might be a state
>issue,
>since WINS is hard coded as soon as the machine comes online it may have a
>previous state entered before I connect to the VPN.  Once connected it
>continues to pass the traffic in clear per the previous state.  Once this
>times out then it creates a new state which redirects it through the
>tunnel.
>I also couldn't find the SK article you mentioned on secure track.  I keyed
>it in, but it couldn't find results.  Do you have the HREF handy?
>
>Derek O'Flynn
>Enterprise Information Security
>LSU Health Sciences Center
>[EMAIL PROTECTED] (504)568-6130
>
>-----Original Message-----
>From: Ray Pesek [mailto:[EMAIL PROTECTED]
>Sent: Monday, June 07, 2004 8:09 PM
>To: [EMAIL PROTECTED]
>Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site en
>cryption domain
>
>Thanks, Derek. That's pretty much the way it's working. We took great pains
>on both ends to assure that only this one IP on each end could be accessed
>via the VPN, so including the web server in the VPN opens a whole host of
>other issues. We don't need HTTP over the VPN, so it looks like the best
>interim solution is to just exclude the HTTP service.
>
>This certainly is a pain, though. If there is no access allowed in the "if
>via" rule, then it shouldn't matter. In my opinion, anyway.  :-) Or let me
>define the encryption domain on my side for each VPN community. That would
>be very nice!
>
>We do need the web server in the encryption domain for other site-to-site
>VPNs we're planning.
>
>BTW, did you get anywhere on your WINS issue?
>
>Take care,
>
>Ray
>
>
> >From: "O'Flynn, Derek" <[EMAIL PROTECTED]>
> >Reply-To: Mailing list for discussion of Firewall-1
> ><[EMAIL PROTECTED]>
> >To: [EMAIL PROTECTED]
> >Subject: Re: [FW-1] Remote Access encryption domain versus site-to-site
>en
> >cryption domain
> >Date: Mon, 7 Jun 2004 17:56:10 -0500
> >
> >We have had a similar issue.
> >
> >We have a site to site VPN setup with an external site.
> >
> >Servers needing access are defined on the if via rule.
> >
> >Encryption domain on our side includes subnets at my site.
> >
> >The difference lies, in that the web server we try to get to is on the
> >external site's network.
> >
> >We could not get to their website.  I believe the packet was dropped.
> >Reason was that the website was included in the encryption domain of the
> >external site and CheckPoint would include it in the VPN rule and this
>site
> >did not have access via the rule and would get dropped.
> >
> >We found out that we had defined the encryption domain for the external
> >site
> >incorrectly.  Once we corrected this, they were able to access the
>website.
> >
> >So I believe that if your webservers are included in your encryption
>domain
> >you will see the same issue.  It is possible that you could create a
> >network
> >object with your defined subnets for the encryption domain, and then use
>a
> >negate group to negate the web server from the encryption domain, and
>apply
> >this to the topology.  But of course this has other issues...where you
>need
> >the web server as part of the encryption domain.
> >
> >Another thing you could try is include this webserver as part of the site
> >to
> >site VPN with the other site, then instead of them coming cleartext to
>the
> >site, they would come through the VPN.
> >
> >Derek O'Flynn
> >Enterprise Information Security
> >LSU Health Sciences Center
> >[EMAIL PROTECTED] (504)568-6130
> >
> >-----Original Message-----
> >From: Ray Pesek [mailto:[EMAIL PROTECTED]
> >Sent: Monday, June 07, 2004 1:33 PM
> >To: [EMAIL PROTECTED]
> >Subject: [FW-1] Remote Access encryption domain versus site-to-site
> >encryption domain
> >
> >We have our entire internal network defined as being in the encryption
> >domain for remote access use.
> >
> >We also have a frame connection to a partner that terminates on a server
>in
> >the encryption domain. We want to replace it with a site-to-site
>Simplified
> >VPN. They're running a WatchGuard 7.0 Firebox III system.
> >
> >We got the VPN up and running OK but we have one oddity. We also have a
>web
> >server on our internal network (in the encryption domain) that is
> >accessible
> >from certain IP addresses on the Internet. It is also used by this
>partner.
> >
> >When the partner tries to access the web server from the Internet, the
> >connection is dropped as a cleartext packet in an encrypted connection.
>If
> >I
> >exclude HTTP from the Simplified Community, it works OK.
> >
> >It appears that the Remote Access and Site-to-Site encryption domains
> >cannot
> >be separated at all even though the rule that has the "if via" objects in
> >Source and Destination only specifiy a particular IP address.
> >
> >I was thinking that if the "if via" rule did not specify the IP address
>of
> >the web server, and it doesn't, then traffic to the web server would not
> >have to go down the tunnel as well. The VPN server and the web server are
> >only one digit different in IP addresses, if that matters.
> >
> >Can anyone shed some light on whether this behavior is correct? That if
> >traffic originates from a Simplified VPN satellite gateway, then all
> >traffic
> >to any IP contained in the encryption domain must be encrypted even if
>the
> >rule base does not specify this? R55, by the way.
> >
> >Thanks,
> >
> >Ray
> >
> >_________________________________________________________________
> >Check out the coupons and bargains on MSN Offers!
>http://youroffers.msn.com
> >
> >=================================================
> >To set vacation, Out-Of-Office, or away messages,
> >send an email to [EMAIL PROTECTED]
> >in the BODY of the email add:
> >set fw-1-mailinglist nomail
> >=================================================
> >To unsubscribe from this mailing list,
> >please see the instructions at
> >http://www.checkpoint.com/services/mailing.html
> >=================================================
> >If you have any questions on how to change your
> >subscription options, email
> >[EMAIL PROTECTED]
> >=================================================
> >
> >=================================================
> >To set vacation, Out-Of-Office, or away messages,
> >send an email to [EMAIL PROTECTED]
> >in the BODY of the email add:
> >set fw-1-mailinglist nomail
> >=================================================
> >To unsubscribe from this mailing list,
> >please see the instructions at
> >http://www.checkpoint.com/services/mailing.html
> >=================================================
> >If you have any questions on how to change your
> >subscription options, email
> >[EMAIL PROTECTED]
> >=================================================
>
>_________________________________________________________________
>Stop worrying about overloading your inbox - get MSN Hotmail Extra Storage!
>http://join.msn.click-url.com/go/onm00200362ave/direct/01/
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out-Of-Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================

_________________________________________________________________
FREE pop-up blocking with the new MSN Toolbar - get it now!
http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to