<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 Mobile Access - File Share in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25914#M13213</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should be in the &lt;A href="https://community.checkpoint.com/space/2056"&gt;Remote Access&lt;/A&gt;‌ space.&lt;/P&gt;&lt;P&gt;I'd recommend following the troubleshooting steps for File Shares here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104577" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104577"&gt;ATRG: Mobile Access Blade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Sep 2018 04:38:49 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-11T04:38:49Z</dc:date>
    <item>
      <title>R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25913#M13212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I configured a file share following the Mobile Access R80.10 Administration Guide (&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/159420.htm#o159399" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_MobileAccess_AdminGuide/159420.htm#o159399"&gt;Mobile Access Applications&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When logging in to the SSLVPN portal I'm presented with the following:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70157_pastedImage_13.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I enter '\\unix-01\public' it denies access:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70153_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I however enter '\\192.168.1.3\public' it works perfectly...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobile Access name resolution for the gateway is configured:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70154_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running a tcpdump on 192.168.1.3 (Samba AD Server) shows the DNS query being answered, with no other connections arriving:&lt;/P&gt;&lt;PRE style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 13px;"&gt;[davidh@unix-01 ~]# tcpdump -i eth0 host 100.127.254.1 -nn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;05:45:02.597653 IP 100.127.254.1.58998 &amp;gt; 192.168.1.3.53: 38186+ A? unix-01.lair.co.za. (36)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;05:45:02.598026 IP 192.168.1.3.53 &amp;gt; 100.127.254.1.58998: 38186* 1/2/2 A 192.168.1.3 (120)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;2 packets captured&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;2 packets received by filter&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 13px;"&gt;0 packets dropped by kernel&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mobile Access log is generated:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-7 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70158_pastedImage_14.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Legacy Mobile Access policy should be allowing anything and everything:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70156_pastedImage_12.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other observations:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Not sure why it resolves unix-01.lair.co.za when the Mobile Access name resolution is configured for a domain of 'ad.lair.co.za' but both unix-01.lair.co.za and unix-01.ad.lair.co.za resolve to 192.168.1.3 when querying 192.168.1.3 or 192.168.1.5.&lt;/LI&gt;&lt;LI&gt;Accessing the UNC path using an IP (\\192.168.1.3\public) results in nothing being logged anywhere.&lt;/LI&gt;&lt;LI&gt;Access deny rule record contains the share name twice, as shown above.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 03:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25913#M13212</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-11T03:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25914#M13213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should be in the &lt;A href="https://community.checkpoint.com/space/2056"&gt;Remote Access&lt;/A&gt;‌ space.&lt;/P&gt;&lt;P&gt;I'd recommend following the troubleshooting steps for File Shares here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104577" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104577"&gt;ATRG: Mobile Access Blade&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 04:38:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25914#M13213</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-11T04:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25915#M13214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks, I followed the debug steps in the 'Troubleshooting Topic: File Shares' section and compared a debug when attempting to access \\unix-01\public to \\192.168.1.3\public. The first instance doesn't record anything whilst the 2nd initiates 'RpcServer::newConnection', which details the following in the Request section:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;[CvpnProcServer 11021 4135978768]@fwcp1[12 Sep 21:52:08] Request: (&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;:method (RunProcReq)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;:params (RpcProcRequest&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:m_cookie (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value (***)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:m_processName (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value ("/opt/CPcvpn-R80/bin/Mount")&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:m_args (vector&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value (192.168.1.3)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value (public)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value ("/opt/CPcvpn-R80/mnt/cvpn_mnt/ml0")&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value (davidh)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: (string&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;:value (50232a6b27653d4f)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: (string&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; :value (ad.lair.co.za)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;)&lt;BR /&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We run split horizon DNS to resolve names differently outside of our network to within, the problem appears to be that&amp;nbsp;Mobile Access&amp;nbsp;name server definitions simply get added to /etc/resolv.conf, which results in Gaia recursively attempting to resolve the name in the UNC path using the default DNS search domain:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 12px;"&gt;[Expert@fwcp1:0]# cat /etc/resolv.conf&lt;BR /&gt;# This file was AUTOMATICALLY GENERATED&lt;BR /&gt;# Generated by /bin/resolv_xlate on Mon Sep 10 20:45:34 2018&lt;BR /&gt;#&lt;BR /&gt;# DO NOT EDIT&lt;BR /&gt;#&lt;BR /&gt;search lair.co.za&lt;BR /&gt;nameserver 41.79.20.1&lt;BR /&gt;nameserver 41.79.21.1&lt;BR /&gt;#start SSLVPN name servers from Smart Dashboard&lt;BR /&gt;nameserver 192.168.1.3&lt;BR /&gt;nameserver 192.168.1.5&lt;BR /&gt;#end SSLVPN name servers from Smart Dashboard&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 12px;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;What's confusing is that Gaia sends DNS queries for 'unix-01.lair.co.za' to both the public caching DNS servers as well as the&amp;nbsp;private AD DNS servers (Samba Active Directory), but then doesn't attempt connecting to either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got it working by clearing the Mobile Access Name Resolution settings and configuring the DNS servers to reference the internal DNS servers in 'clish':&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 12px;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70221_gateway_settings.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clish:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;set dns primary 192.168.1.3&lt;BR /&gt;set dns secondary 192.168.1.5&lt;/SPAN&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace; font-size: 12px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the intended behaviour? I would have assumed the gateway to be configured to use public caching DNS servers and the Mobile Access name resolution settings to be used for the SSL VPN portal...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 20:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25915#M13214</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-12T20:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25916#M13215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The above DNS servers are for clients that connect with SNX, not for the MAB portal itself, which would use the Gaia OS settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 20:49:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25916#M13215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-12T20:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25917#M13216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I recommend you login to the gateway in question with SSH and see what happens if you type ping unix01&lt;/P&gt;&lt;P&gt;If that fails you know why it failed in you Mobile Access connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 10:23:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/25917#M13216</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2018-09-13T10:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 Mobile Access - File Share</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/49705#M13217</link>
      <description>&lt;P&gt;&lt;SPAN&gt;SMBv2/v3 doesnot support,&amp;nbsp;Once the gateway supports a newer kernel&amp;nbsp;(like is planned for R80.20), it should be possible to support SMBv2/v3. you can find the details at the link below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SandBlast-Mobile/SMBv2-v3-on-Mobile-Access-File-Share-and-not-only-SMBv1-CIFS/m-p/30829" target="_blank" rel="noopener"&gt;https&lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;/community.checkpoint.com/t5/SandBlast-Mobile/SMBv2-v3-on-Mobile-Access-File-Share-and-not-only-SMBv1-CIFS/m-p/30829&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 16:41:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/R80-10-Mobile-Access-File-Share/m-p/49705#M13217</guid>
      <dc:creator>Ozgur</dc:creator>
      <dc:date>2019-04-03T16:41:18Z</dc:date>
    </item>
  </channel>
</rss>

