Checkpoint VPN client does not use ESP but some UDP port for enrypted data

Checkpoint VPN client does not use ESP but some UDP port for enrypted data

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Checkpoint VPN client does not use ESP but some UDP port for enrypted data andipfaff 07-28-2006
Posted by andipfaff on July 28, 2006, 10:02 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

today we tried to solve a problem with a Checkpoint VPN client behind a
Cisco ADSL router with access list on the WAN interface. I had to open
ALL UDP ports, because the VPN client sends encrypted data not with ESP
like expecte but with UDP packets with random port numbers. There is a
way to configure NAT traversal etc. but in fact this affects just the
ISAKMP encryption. Doing the same on the Cisco VPN client does what I
want: ISAKMP alway with UDP 500/500, data via ESP, UDP 4500 or TCP
10000 (depending on the settings).

Is there a way to send encrypted data with ESP on the checkpoint
client? I am not willing to let open all the incoming UDP ports!

thanks in advance
Andi


Posted by optikl on July 28, 2006, 11:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options
andipfaff wrote:
> Hi,
>
> today we tried to solve a problem with a Checkpoint VPN client behind a
> Cisco ADSL router with access list on the WAN interface. I had to open
> ALL UDP ports, because the VPN client sends encrypted data not with ESP
> like expecte but with UDP packets with random port numbers. There is a
> way to configure NAT traversal etc. but in fact this affects just the
> ISAKMP encryption. Doing the same on the Cisco VPN client does what I
> want: ISAKMP alway with UDP 500/500, data via ESP, UDP 4500 or TCP
> 10000 (depending on the settings).
>
> Is there a way to send encrypted data with ESP on the checkpoint
> client? I am not willing to let open all the incoming UDP ports!
>
> thanks in advance
> Andi
>

This probably isn't the answer you want, but have you thought about
converting to just Cisco VPN clients?

Posted by Dataway on July 28, 2006, 3:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi Andi,

I work for Dataway, Inc. We are a network security firm, and partnered
with both Check Point and Cisco. We have extensive experience with
VPN's on both and between both. If you would like assistance with
this, I can help you. Please feel free to give me a call at
415.659.1720 to discuss.

Best Regards,

Jason


andipfaff wrote:
> Hi,
>
> today we tried to solve a problem with a Checkpoint VPN client behind a
> Cisco ADSL router with access list on the WAN interface. I had to open
> ALL UDP ports, because the VPN client sends encrypted data not with ESP
> like expecte but with UDP packets with random port numbers. There is a
> way to configure NAT traversal etc. but in fact this affects just the
> ISAKMP encryption. Doing the same on the Cisco VPN client does what I
> want: ISAKMP alway with UDP 500/500, data via ESP, UDP 4500 or TCP
> 10000 (depending on the settings).
>
> Is there a way to send encrypted data with ESP on the checkpoint
> client? I am not willing to let open all the incoming UDP ports!
>
> thanks in advance
> Andi


Similar ThreadsPosted
Checkpoint Firewall-1 altering packet data: January 23, 2008, 12:05 am
Checkpoint Secure Client and WPA February 17, 2005, 1:50 pm
CheckPoint and Secure Client May 26, 2005, 1:07 am
(Checkpoint) VPN client for Windows Mobile 5? April 18, 2006, 1:10 pm
VPN-1 CheckPoint Linux client -- no longer supported? May 31, 2007, 6:33 pm
Zone Alarm Pro on server denying client access to 'Net from client laptop October 15, 2006, 12:51 pm
checkpoint secure remote tcp port 9000 July 29, 2004, 11:20 am
Microsoft Firewall client and Cisco VPN Client June 23, 2005, 9:45 am
my computer is sending a lot of data out but I am not uploading? August 2, 2004, 5:34 pm
Why does my Network Win XP constantly send data to each other??? December 9, 2005, 5:28 am

The site map in XML format XML site map

Contact Us | Privacy Policy