- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Recently migrated from a Cisco ASA to a CP3800 R82. With the Cisco we were able to reach the VPN clients with traffic initiated from the Lan. This isn't happening with the CP. Logs show Lan initiated traffic being encrypted on the gateway, but that is where it ends. I don't have a NAT setup at this time between the VPN subnet and Lan. Not sure if that is the missing piece or it's something else.
Policy rules:
1. source: vpn@any, dest: intLan, VPN: RemoteAccess, Serv&app: Any, Action: Accept
2. source: intLan, dest: Any, VPN: Any, Serv&app: Any, Action: Accept
3. source: VPNsubnet, dest: intLan, VPN: Any, Serv&app: Any, Action: Accept
4. Cleanup rule
Added Rule #3 but didn't make a difference.
If the Endpoint Client only applies policy assigned to the VPN community (RemoteAccess), then that would explain what is happening.
Thanks for any help.
By default, this is blocked in Global Properties.
Enable Back Connections and push policy.
That is currently enabled.
Now that I re-read your post, I believe NAT could be the issue. Make sure vpnsubnet object is natted in smart console, just do behind gateway.
Andy
Just to make sure Im not missing anything...are you saying when people connect with VPN client, they cant access anything behind the fw?
Andy
VPN clients when connected, can access anything just fine on the network, without a NAT. It's when for example my PC on the Lan tries to connect to a VPN client, that it does not work. Ping, remote desktop, anything....does not work.
Ah, got it now...so can you do this when trying on the fw (or if its cluster, whichever is active atm)
fw ctl zdebug + drop | grep x.x.x.x
Just replace x.x.x.x with IP you are trying to connect to
ctrl+c to stop
Andy
Nothing showed up in dubug on the cluster. Attached log showing traffic being encrypted to the vpn client.
Checked trac logs on the client, nothing with my source IP in it.
Client is E88.30
Now that I think about it, lets start with basics, as they say.
1) what subnet is assigned for vpn clients?
2) when connection fails to connect back from lan, what do you see when running route print from your machine?
3) If you run ip r g and then IP of the vpn client, does it show correct info? ie : ip r g 10.10.10.50
4) if no drops are observed, then we can say with high confidence that rules are fine, but to be 100% sure, you can run example 1 from below link on the fw itself, just add dst IP as well, ipp can be 0
Andy
Can you attach full log please? Also, maybe worth trying E89 client version as a test.
Andy
I meant smart console log.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 42 | |
| 18 | |
| 12 | |
| 11 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY