Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Firewalls
[Top] [All Lists]

RE: CHECKPOINT VPN Client

Subject: RE: CHECKPOINT VPN Client
Date: Sun, 27 Nov 2005 20:41:10 -0600
Hi

Well, maybe you should check for the protocols 50 and 51, and the IKE port
(UDP 500, and TCP 500 in case you send IKE over TCP). Try adding this rule
separately, do not use ANY. That should do it for the services question.

However, you also need to check in the VPN gateway 3 more possible errors
that you should address in order to get your remote acces correct:

1.- Overlapping, in case your private network at home matches with any other
within the enterprise network, then you will need to NAT your private IP at
home or change your home network to another one that do not match in your
enterprise network which leads to No.2
2.- Antispoofing, in case your private network at home is within the
enterprise network
3.- Routing, in case your private network at home is not routed at your
enterprise network, and you're not using IP pool NAT

It is more recommended to use IP pool NAT since you control the IP you
assign to external networks, instead of routing multiple private networks to
the Internet, which may lead to security issues (don't forget the ARP).

Hope this helps

OA

-----Original Message-----
From: Alexis Villagra - VILSOL LatinAmerica
To: firewalls@securityfocus.com
Sent: 25/11/2005 01:39 a.m.
Subject: CHECKPOINT VPN Client
Importance: High

Hi,
 
I have a CheckPoint VPN Client installed in my PC at home, when i
connect to Internet directly i can connect to my VPN Server in the main
office.
I have bought a firewall, i left default services open but i can not
establish a VPN connection.
 
Could you tell me which ports or what should I do in the firewall to
allow the establishment of the VPN connection.
 
Best regards,
ALEXIS VILLAGRA

<Prev in Thread] Current Thread [Next in Thread>