Popular
Latest Articles
ASA L2L VPN is not passing traffic when a VPN Filter is applied
Within the Cisco Adaptive Security Appliance Software Version 8.2(2) you may find that when you have a group-policy (vpn filter) applied to your tunnel group that some traffic is not being allowed through the VPN.
This is a bug with 8.2(2) for which to resolve the issue you will need add the destination ports to the group-policies access-list.
Examples
Your previous access-list entry for your group-policy may of look liked this :
Below is an example of the config that you would need to add in order to get traffic working which is being affected by this bug,
Below is an example of the complete config. Please note this only includes the complete config for the group-policy and the relevant tunnel group and not the vpn configuration) :
Please Note : If this does not resolve your issue please refer to the Cisco Bug Tracker. This is just one of a number of bugs included within the vpn filter feature.
Endpoint Connect Installation / Troubleshooting Guide
What is EndPoint Connect ?
Checkpoint`s Endpoint Connect software provides a number of client side security based features such as Anti-virus/Anti-spyware. Firewall/Email Protection, Program Control and Remote Access VPN. This document will only details and discuss the Remote Access VPN section of the Endpoint Connect Software. Note : This document will refer to the Endpoint Connect Remote Access VPN as just Endpoint Connect.
Endpoint Connect is built into the software for mangers and gateways running R70 and above. For R65 gateways that require Endpoint Connect a few additional configuration steps are required which are included within this document.
Please note : This testing and documentation is based on the Endpoint Connect R73 Client.Advantages
- Lightweight Client if you are using a single site or single entry point setup.
- Can be installed onto Windows 7 64-bit.
Disadvantages
- An additional SNX (SSL Network Extender License) is required due to that in which it authenticates across HTTPS (vistor mode)
- Link Selection is disabled (this is due to sites being defined via a single IP address).
- MEP configurations can only be achieved by using Geo-Cluster DNS name resolution.
Installation on an R65 Gateway
Upgrading a R65 Gateway to R65 Endpoint Connect:
- Ensure that you are running HFA40 or higher.
- Ensure that you are managing the gateway with R70 or higher.
You will now be able to configure the require Endpoint Connect settings via the Smart Dashboard.
Configuration
To enable Endpoint Connect configure/enable the following settings :
Under the Checkpoint Gateway Object
1. Enable VPN
2. Create a VPN domain
3. Enable NAT-T
4. Enable Visitor Mode :
5. Enable Office mode
6. Enable SSL Network Extender
7. Endpoint connect doesn`t support DES. If this is set please re-configure.
Additional Settings
Further settings can be set within the Global Properties:
Troubleshooting
Issue : Authenticating failed: GEN_application_error(0)
You may receive this error when trying to login.
This is down to your client being unable to authenticate with the VPN gateway using HTTPS. This can be caused by the following:
1. Port 443/tcp on the firewall is assigned to a web management GUI (WEBUI/Voyuger) instead of VPND.
2. Port 443/tcp is not listening due to no SNX (SSL Network Extender) License being present.
Issue : Failed to download topology
Endpoint Connect fails to connect to NGX R65 Security Gateways that are managed by an R70 Security Management server with error: "failed to download topology".
To resolve this run through the following steps :1. On the R70 Security Management server, edit the file: 2. Scroll down to the section that starts with: 3. Add the entry for the ccc_sessions table below it: 4. After adding this entry to the vpn_table.def file, open SmartDashboard and re-install policy to the NGX R65 Security Gateway(s).
Further details can be found within the Checkpoint KB article sk43124
Licensing
Details on licensing can be found within Checkpoints KB article sk43329.
Checkpoint Web Visualization only provides part of the policy
When using the Checkpoint Web Visualization tool and trying to obtain the policy for a Cluster object you may receive one of the following errors/issues :
- The policy is saved as an .html file but it is only showing part of the policy.
- You receive one of the following errors when running the Web Visualization syntax:
Solution
To resolve the issue use the cluster object name rather then the individual cluster node name when using the Web Visualization command. An example would be :
Running a packet capture on a SourceFire Sensor
Below shows you the required steps for running a packet capture on a SourceFire Sensor.
Which Interfaces are Sniffing ?
First of all we get a list of interfaces that is are sniffing for malicious traffic. Note : the fps normally relate to eth. Though you still use the fps reference within the tcpdump.
Tcpdump the Interface
Using the interface numbers output from the last command you can now use these to run a tcpdump.
Example: Overview of trafficWe can also get an overview of the traffic by running the following command,
File download fails through Netscreen when using IE6 with Passive FTP
Firewalls - Juniper - Netscreen
You may find when trying to download a file from your FTP server using Internet Explorer 6 with "Folder View Enabled" when using Passive FTP the file download transfer will fail after a short time period.
This can be down to Internet Explorer sending TCP packets with sequence numbers which are outside that of the current TCP window. This in turn causes the FTP file transfer to fail. This can be caused by vendors using non-RFC methods to verify a packets validity or the host sending back badly number packets expecting a return.
You can confirm whether the Netscreen is dropping packets due to this with the following command,
Solution
The Netscreen is working by design so you have 3 options :
- Disabling TCP sequence checking on the firewall using the command 'set flow no-tcp-seq-check'
- Using an alternative client for Passive FTP downloads.
- Using Active FTP
Page 1 of 38
«StartPrev12345678910NextEnd»