Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BrianD
Participant

SmartConsole Access over Site-to-Site

We have a S2S from corporate to our COLO where the Checkpoint lives. The assets on the management network, 192.168.110.0/24 are pingable and we can even browse SMB across the tunnel. Confirming that the S2S is up and traffic from our local network and the management network of where the Checkpoint sits is flowing.

Another small fact is if I dial into the Checkpoint, using our Checkpoint mobile VPN client, I can attach my locally installed SmartConsole to the CP.

 

Why is it that with the S2S up, I can't attach to the CP using my locally installed SmartConsole even though the traffic on the S2S is flowing freely?

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

My guess is implied rules OR you’ve restricted what IPs can connect via SmartConsole (done via cpconfig).
What precise drops do you see in the logs when you attempt this?

0 Kudos
BrianD
Participant

CP: 192.168.110.248

My computer: 10.10.10.120

CP logs show traffic from my computer to various assets in the CP network (192.168.110.0/24) but does not reflect my attempts of connecting to the CP via smart console.

The following screenshot shows the logs - it even shows the blocking of ICMP packets because I'm running a constant tracert. But it does not show anything related to my attempts of connecting with SmartConsole.

2021-11-05_14-30-00.png

 

0 Kudos
Danny
Champion Champion
Champion

Check the logs of your corporate Site-to-Site VPN gateway.
It's probably only allowing standard services such as ping, dns etc. to your COLO with the Check Point firewall.

0 Kudos
Baasanjargal_Ts
Advisor
Advisor

Hello

You need to look sk105719. That will be helpful for you.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events