HELP!  -  Check Point Firewall and Nortel VPN client  =  Banner Text Hanging

HELP! - Check Point Firewall and Nortel VPN client = Banner Text Hanging

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
HELP! - Check Point Firewall and Nortel VPN client = Banner Text Hanging me 11-26-2005
Posted by on November 26, 2005, 4:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I was hoping someone might be able to provide any help with this?

We recently upgraded our crappy little firewall (3com) to a
Nokia/Check point firewall (NG with AI). Before the upgrade, we had
some PC's that had a VPN connection off-site using Nortel VPN client
connecting to a Nortel VPN box.

After the upgrade, this has failed to work, and always hangs at
'Retrieving Banner Text.' I have done loads of searching on the net,
and so far have tried just about everthing I could find on the
subject. I have been speaking to a person who knows Check Point, and
he mentioned something about NAT Traversal over TCP that would fix the
problem, but I'm not sure where to configure this in the Dashboard?

I have these protocols enabled:

ESP                 (50)
IKE                 (500)
IKE_TCP         (500)
AH                 (51)
Port 10000         (UDP & TCP)
Port 10001         (UDP)
Port 17                 (UDP & TCP)
Port 2746 (UDP)

The VPN clients WILL connect however, if I assign the PC it's own
external IP address. As we do not have unlimited external IP's, that
really is not an option.

Any help, tips or pointers would be very much appreciated!


JL

Posted by Triffid on November 26, 2005, 6:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


me@the.computer wrote:
> Hello,
>
> I was hoping someone might be able to provide any help with this?
>
> We recently upgraded our crappy little firewall (3com) to a
> Nokia/Check point firewall (NG with AI). Before the upgrade, we had
> some PC's that had a VPN connection off-site using Nortel VPN client
> connecting to a Nortel VPN box.
>
> After the upgrade, this has failed to work, and always hangs at
> 'Retrieving Banner Text.' I have done loads of searching on the net,
> and so far have tried just about everthing I could find on the
> subject. I have been speaking to a person who knows Check Point, and
> he mentioned something about NAT Traversal over TCP that would fix the
> problem, but I'm not sure where to configure this in the Dashboard?

I use UDP encapsulated IPSEC for NAT traversal. You configure that on
the Nortel. I also have the Nortel outside the Checkpoint so the
firewall can inspect the traffic after it comes out of the tunnel.

I suspect the hang at 'Retrieving Banner Text' is a red herring, since
that uses UDP 10001 - which you already have open.

> I have these protocols enabled:
>
> ESP                 (50)
> IKE                 (500)
> IKE_TCP         (500)
> AH                 (51)
> Port 10000         (UDP & TCP)
> Port 10001         (UDP)
> Port 17                 (UDP & TCP)
> Port 2746 (UDP)
>
> The VPN clients WILL connect however, if I assign the PC it's own
> external IP address.

Sounds like a routing problem, doesn't it.

Triffid

> As we do not have unlimited external IP's, that
> really is not an option.
>
> Any help, tips or pointers would be very much appreciated!
>
>
> JL

Posted by on November 29, 2005, 4:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for your help Triffid. The Nortel box is out of our control,
so I'll have to find out what they've got setup.

It's one of those things, that is so close to finding the answer..

JL

wrote:

>
>
>me@the.computer wrote:
>> Hello,
>>
>> I was hoping someone might be able to provide any help with this?
>>
>> We recently upgraded our crappy little firewall (3com) to a
>> Nokia/Check point firewall (NG with AI). Before the upgrade, we had
>> some PC's that had a VPN connection off-site using Nortel VPN client
>> connecting to a Nortel VPN box.
>>
>> After the upgrade, this has failed to work, and always hangs at
>> 'Retrieving Banner Text.' I have done loads of searching on the net,
>> and so far have tried just about everthing I could find on the
>> subject. I have been speaking to a person who knows Check Point, and
>> he mentioned something about NAT Traversal over TCP that would fix the
>> problem, but I'm not sure where to configure this in the Dashboard?
>
>I use UDP encapsulated IPSEC for NAT traversal. You configure that on
>the Nortel. I also have the Nortel outside the Checkpoint so the
>firewall can inspect the traffic after it comes out of the tunnel.
>
>I suspect the hang at 'Retrieving Banner Text' is a red herring, since
>that uses UDP 10001 - which you already have open.
>
>> I have these protocols enabled:
>>
>> ESP                 (50)
>> IKE                 (500)
>> IKE_TCP         (500)
>> AH                 (51)
>> Port 10000         (UDP & TCP)
>> Port 10001         (UDP)
>> Port 17                 (UDP & TCP)
>> Port 2746 (UDP)
>>
>> The VPN clients WILL connect however, if I assign the PC it's own
>> external IP address.
>
>Sounds like a routing problem, doesn't it.
>
>Triffid
>
>> As we do not have unlimited external IP's, that
>> really is not an option.
>>
>> Any help, tips or pointers would be very much appreciated!
>>
>>
>> JL

Posted by on November 29, 2005, 7:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for your help Triffid. The Nortel box is out of our control,
so I'll have to find out what they've got setup.

It's one of those things, that is so close to finding the answer..

JL

wrote:

>
>
>me@the.computer wrote:
>> Hello,
>>
>> I was hoping someone might be able to provide any help with this?
>>
>> We recently upgraded our crappy little firewall (3com) to a
>> Nokia/Check point firewall (NG with AI). Before the upgrade, we had
>> some PC's that had a VPN connection off-site using Nortel VPN client
>> connecting to a Nortel VPN box.
>>
>> After the upgrade, this has failed to work, and always hangs at
>> 'Retrieving Banner Text.' I have done loads of searching on the net,
>> and so far have tried just about everthing I could find on the
>> subject. I have been speaking to a person who knows Check Point, and
>> he mentioned something about NAT Traversal over TCP that would fix the
>> problem, but I'm not sure where to configure this in the Dashboard?
>
>I use UDP encapsulated IPSEC for NAT traversal. You configure that on
>the Nortel. I also have the Nortel outside the Checkpoint so the
>firewall can inspect the traffic after it comes out of the tunnel.
>
>I suspect the hang at 'Retrieving Banner Text' is a red herring, since
>that uses UDP 10001 - which you already have open.
>
>> I have these protocols enabled:
>>
>> ESP                 (50)
>> IKE                 (500)
>> IKE_TCP         (500)
>> AH                 (51)
>> Port 10000         (UDP & TCP)
>> Port 10001         (UDP)
>> Port 17                 (UDP & TCP)
>> Port 2746 (UDP)
>>
>> The VPN clients WILL connect however, if I assign the PC it's own
>> external IP address.
>
>Sounds like a routing problem, doesn't it.
>
>Triffid
>
>> As we do not have unlimited external IP's, that
>> really is not an option.
>>
>> Any help, tips or pointers would be very much appreciated!
>>
>>
>> JL

Similar ThreadsPosted
Proxy on VPN client for check point? May 31, 2005, 1:29 am
Check Point Firewall October 5, 2005, 6:29 pm
Upgrade a Check Point FW-1/VPN-1 on firewall cluster. August 10, 2004, 6:57 am
Essential Check Point FireWall-1 NG and cisco piX June 25, 2005, 10:49 pm
Can Cisco Content Switching works with firewall cluster (Check Point+ RainWall) ? March 28, 2006, 10:16 pm
Check Point Vs Juniper August 2, 2008, 11:20 am
Check Point SmartCenter Password December 12, 2005, 8:27 am
EIGRP through Check Point firewalls May 19, 2006, 5:37 pm
Check Point Transparent Mode October 2, 2006, 12:11 pm
router for Check Point Secureclient VPN March 21, 2007, 1:13 pm

The site map in XML format XML site map

Contact Us | Privacy Policy