Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RPawar
Contributor

ICPM/Ping shows RTO from user to server while RDP works in Remote VPN

Hello Everyone,

 

I have created a setup where i have two interfaces configured inside & outside the inside interface has a laptop directly connected to it, similarly the outside interface also has a laptop directly connected to it.

Now for the remote vpn setup i have defined a /22 ip pool in office mode settings also i have created local users and those particular users are aligned with static IP in ipassignment.conf file on the GW.

The remote VPN gateway is my outside interface VIP when i connect the remote vpn from static user the connection works and user successfully receives the assigned static IP.

Here is the part where i am facing issue :

For static user i have created a policy which allows static IP of vpn user to be in source and in destination i have kept the machine behind my inside interface in service i have kept RDP & ICMP protocol, reply, request.

when my user connects the vpn client he is able to take RDP successfully however when doing ping he gets RTO.

I checked tcp dump i can see echo request & reply packets coming back from destination.

I also kept service as any and checked still same issue.

I disabled both machine windows firewall
both machines are test machines and don't have any type of EDR/AV

I have defined the inside subnet in the VPN domain 

The setup is :

Smart-1 700S appliance / R82.10 take 40

3970 GW cluster appliances / R82.10 take 22

Can you guys let me know is anyone has faced similar kind of issue? also request you all to assist me to solve this.

 

0 Kudos
3 Replies
Martijn
MVP Platinum
MVP Platinum

Hi,

First thing that comes to mind is Implied Rules? Are those enabled?
If so, ICMP packets are handeled by the Implied Rule (rule 0) and not by rules configured in the policy.

But maybe you can show us a simple network diagram of you setup and the rules you have configured in the policy.

What is SmartLog showing? Do you see the ICMP packets being logged. If not, enable logging for Implied Rules.

With TCPDUMP you see the ICMP packets? Are you running TCPDUMP on the internal or external network?

Martijn

0 Kudos
RPawar
Contributor

Hello Martijn,

 

Thanks for reply, please find below inputs
Implied rules are kept as by default only i have not changed any thing in it, also i don't see any drop logs based on implied rules.

Also i checked in the logs i can see that request packets are getting properly logged on the remote vpn policy.

I am running TCP dump directly on the remote vpn IP
I have attached the logs and diagram please have a look.

Thanks!

 

 

0 Kudos
Martijn
MVP Platinum
MVP Platinum

Hi,

I assume the TCPDUMP output is from the internal interface of the gateway. Correct?

So it looks like the packets arrive on the internal interface but are not encrypted back into the VPN.
Can you check with 'fw monitor' to see what is happening on the outside interface?

These post from @WiliRGasparetto can help:

fw monitor Under the Hood — Part 1: What i, I, o, ... - Check Point CheckMates

fw monitor Deep Dive — Part 2: NAT, VPN and Packet... - Check Point CheckMates

What is the default gateway of your firewall? When I created this setup (VPN client directly connected to the outside interface), I only cloud get it to work if the default gateway of the firewall was pointing to the VPN client and the default gateway of the VPN client was pointing to the firewall. I know, this sounds strange but it was the only way to get it to work.

Hope 'fw monitor' can point you to the right direction.

Martijn



0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events