Here is some updated information. I tried to establish the VPN from a client that was not behind a firewall and not being NATed to rule that out as an issue. I have also attached the log file for review. 69.x.85.63 is the IP address of the VPN client, x.x.4.6 is the IP address that is assigned to the firewall and is the internal interface of the firewall, x.x.4.66 is the external IP address of the firewall, and x.x.2.50 is a system in my encryption domain that the VPN client attempts to access.
It seems to me like the client authenticates to .4.6 and the IPSEC tunnel is established with 4.66. Is this correct? Then when the client attempts to access .2.50 the traffic is dropped because the IKE traffic has not been established with the correct IP address? Any ideas on what I should look at? Thanks!
Log also below:
"Number" "Date" "Time" "Product" "Interface" "Origin" "Type" "Action" "Service" "Source" "Destination" "Protocol" "Rule" "Source Port" "User" "Information" "420068" "30Jun2004" "20:11:11" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "tcp" "1" "3744" "" "" "420077" "30Jun2004" "20:11:13" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Login" "" "69.x.85.63" "" "" "0" "" "vpntest" "reason: Client Encryption: Authenticated by Internal Password; " "420080" "30Jun2004" "20:11:13" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Login" "" "69.x.85.63" "x.x.4.6" "" "0" "" "vpntest" "reason: User authenticated by Firewall. Sending SSL Encrypted Topology, using IKE authentication.; " "420247" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "420249" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; " "420253" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "2746" "69.x.85.63" "x.x.4.66" "udp" "1" "3738" "" "" "420679" "30Jun2004" "20:12:45" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "2746" "69.x.85.63" "x.x.4.66" "udp" "1" "3738" "" "" "425874" "30Jun2004" "20:20:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "425876" "30Jun2004" "20:20:43" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; " "430163" "30Jun2004" "20:28:01" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Drop" "500" "69.x.85.63" "x.x.2.50" "tcp" "40" "45205" "" "" "430266" "30Jun2004" "20:28:13" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Drop" "500" "69.x.85.63" "x.x.2.50" "tcp" "40" "45206" "" "" "430928" "30Jun2004" "20:29:55" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "430929" "30Jun2004" "20:29:56" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; "
From: Gus Fritschie <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: Re: [FW-1] problems with SecuRemote Date: Tue, 29 Jun 2004 18:58:58 -0400
10.1.1.2 is the IP address of my SecuRemote computer that is on my home network behind a PIX 501 that is doing NAT and my DSL modem. I do have both IKE over TCP and/or UDP encapsulation selected on my VPN client. 138.88.46.143 is the IP address assigned by my ISP. Not sure what else I should do?
From: Chris Hoff <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: Re: [FW-1] problems with SecuRemote Date: Fri, 25 Jun 2004 09:48:39 -0500
Gus,
If you notice, the host that is getting authenticated is 10.1.1.2. However, the traffic destined for the internal network is from 138.88.46.143 (pool-138-88-46-143.res.east.verizon.net). You might get through by either forcing IKE over TCP and/or UDP encapsulation on the client side. This is done the in the Tools>Configure Connection Profile>Advanced tab of the SecuRemote software.
Good luck,
Chris
-----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Gus Fritschie Sent: Wednesday, June 23, 2004 8:23 AM To: [EMAIL PROTECTED] Subject: [FW-1] problems with SecuRemote
I am running Check Point NG FP 3 on Linux 7.3. I am having some problems getting the client to site VPN to work. I have the following rules in my rule base before the stealth rule:
any -> no-fw1 -> any -> fw1_pslogon, FW1_topo, IKE, ESP, VPN1_IPSEC_encapsulation -> accept
all [EMAIL PROTECTED] -> encryption domain -> if via RemoteAccess -> any -> accept
My SecuRemote client can authenticate and connect to the site and download the topology. However, when I try to access a server in my encryption domain, I fail. When looking at the logs I see a drop on IKE_TCP directed at the system I am trying to access. I have attached the logs. Have a setup something wrong with my topology or encryption domain? Any help would be appreciated. Thanks!
Time Interface Origin Action Service Source Destination Protocol User Information 22:16:50 eth1 no-fw1 Accept IKE_tcp pool-138-88-46-143.res.east.verizon.net no-fw1 tcp 22:16:56 daemon no-fw1 Login pool-138-88-46-143.res.east.verizon.net test reason: Client Encryption: Authenticated by Internal Password; 22:16:56 daemon no-fw1 Login pool-138-88-46-143.res.east.verizon.net no-fw1 test reason: User authenticated by Firewall. Sending SSL Encrypted Topology, using IKE authentication.; 22:17:39 eth1 no-fw1 Accept IKE pool-138-88-46-143.res.east.verizon.net no-fw1 udp 22:17:40 daemon no-fw1 Key Install pool-138-88-46-143.res.east.verizon.net no-fw1 test IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 10.1.1.2; 22:17:40 eth1 no-fw1 Accept VPN1_IPSEC_encapsulation pool-138-88-46-143.res.east.verizon.net no-fw1 udp 22:17:42 eth1 no-fw1 Drop IKE_tcp pool-138-88-46-143.res.east.verizon.net 172.x.x.x tcp
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
"Number" "Date" "Time" "Product" "Interface" "Origin" "Type" "Action" "Service" "Source" "Destination" "Protocol" "Rule" "Source Port" "User" "Information" "420068" "30Jun2004" "20:11:11" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "tcp" "1" "3744" "" "" "420077" "30Jun2004" "20:11:13" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Login" "" "69.x.85.63" "" "" "0" "" "vpntest" "reason: Client Encryption: Authenticated by Internal Password; " "420080" "30Jun2004" "20:11:13" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Login" "" "69.x.85.63" "x.x.4.6" "" "0" "" "vpntest" "reason: User authenticated by Firewall. Sending SSL Encrypted Topology, using IKE authentication.; " "420247" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "420249" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; " "420253" "30Jun2004" "20:11:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "2746" "69.x.85.63" "x.x.4.66" "udp" "1" "3738" "" "" "420679" "30Jun2004" "20:12:45" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "2746" "69.x.85.63" "x.x.4.66" "udp" "1" "3738" "" "" "425874" "30Jun2004" "20:20:43" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "425876" "30Jun2004" "20:20:43" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; " "430163" "30Jun2004" "20:28:01" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Drop" "500" "69.x.85.63" "x.x.2.50" "tcp" "40" "45205" "" "" "430266" "30Jun2004" "20:28:13" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Drop" "500" "69.x.85.63" "x.x.2.50" "tcp" "40" "45206" "" "" "430928" "30Jun2004" "20:29:55" "VPN-1 & FireWall-1" "eth1" "x.x.4.6" "Log" "Accept" "500" "69.x.85.63" "x.x.4.66" "udp" "1" "3737" "" "" "430929" "30Jun2004" "20:29:56" "VPN-1 & FireWall-1" "daemon" "x.x.4.6" "Log" "Key Install" "" "69.x.85.63" "x.x.4.6" "" "" "" "vpntest" "IKE: Quick Mode completion; IKE IDs: subnet: 0.0.0.0 (mask= 0.0.0.0) and host: 69.x.85.63; "
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
