- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Office Mode MAC assignment
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Office Mode MAC assignment
Hello,
We use a 3rd party for our DHCP assignment. It bases the leases on the MAC address.
We have noticed that Checkpoint is assigning a new MAC address on reboots and thus getting a new IP/lease assigned to it. This showed up when we ran out of IP's in our pool and saw a lot of machines had 2 or 3 leases.
We have our MAC address for DHCP allocation set to "Unique per machine".
I ran a test of being connected to the vpn and getting an IP, disconnected my connection and reconnected and had the same mac and got the same IP. I then rebooted my laptop and then I got a new mac and thus a new leased IP. Is this normal?
Is there a way of getting a more consistent MAC so a machine doesn't receive a new lease each time?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Hemps
Please check this discussion https://community.checkpoint.com/t5/Remote-Access-VPN/Office-Mode-Algorithm-behind-quot-Unique-per-m...
BR,
Alexander S.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is what it says about that option "unique per machine:...to me, the fact you got the same IP when reconnected sounds right. Upon reboot, it would make sense you got new MAC address, therefore, a new IP address as well. As far as more consistent MAC address, not sire if virtual IP might be an option there.
DHCP allocates IP addresses per MAC address. When VPN needs an Office Mode address, it creates a MAC address that represents the client and uses it in the address request. The MAC address can be unique per machine or per user. If it is unique per machine, then VPN ignores the user identity. If different users work from the same Remote Access client they are allocated the same IP address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @the_rock, are we aware of the algorithm used to allocate this MAC address by Checkpoint when 'Unique per machine' enabled? I am using 87.50 and did not find
"fixed_om_mac_address"="0000" in the path HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\TRAC
For unique per user we know that it uses the first 12 characters of HASH value of the username. In the same way do we know the algorithm behind unique per machine ? thanks in advance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would confirm with TAC in that. I would not know, sorry mate.
Best,
Andy
