Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
Advisor
Jump to solution

keepalive on Endpoint Security

The user upgraded to E88.50 and we are still seeing the issue.  ICMP pings from his PC or router to the gateway.   Is there some kind of keepalive ping check on Endpoint Security I can have him uncheck?   We are trying to figure out what's sending pings back to the remote access gateway (which are dropped) dest-unreach (ICMP).  We don't allow ping.

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend

There is enable always connect, but in order for client to be able to check that, it has to be enabled in global properties, under endpoint options. Except in your case, it should say always connected.

Andy

 

Screenshot_1.png

 

 

Screenshot_2.png

View solution in original post

5 Replies
the_rock
Legend
Legend

Yes, there is and it actually has absolutely zero to do with endpoint version. Its in global properties and its refered to below.

Hope that helps.

Best,

Andy

 

http://downloads.checkpoint.com/dc/download.htm?ID=60345

 

To configure tunnel idleness:

1. Connect to the Security Management Server with GuiDBedit.

2. Open the Global Properties > properties > firewall_properties object.

3. Find disconnect_on_idle and these parameters:

  • do_not_check_idleness_on_icmp_packets

  • do_not_check_idleness_on_these_services - Enter the port numbers for the services that you want to ignore when idleness is checked.

  • enable_disconnect_on_idle - to enable the feature

  • idle_timeout_in_minutes

4. Save and install the policy.

 

Btw, there is ping option there you can change, so if user is somewhat savvy, they can always keep pinging say google dns in cmd and tunnel will NEVER time out, though its supposed to say after 60 mins (just as an example)

Daniel_Kavan
Advisor

Thanks, that 60345 link isn't opening for me.    I'm looking for something to change on the client side actually.   Is there a tunnel keep alive check box for example?

0 Kudos
the_rock
Legend
Legend

There is enable always connect, but in order for client to be able to check that, it has to be enabled in global properties, under endpoint options. Except in your case, it should say always connected.

Andy

 

Screenshot_1.png

 

 

Screenshot_2.png

the_rock
Legend
Legend

@Daniel_Kavan Glad we can help mate. If anything else, just update the thread.

Andy

0 Kudos
_Val_
Admin
Admin

It is just RAS VPN Admin guide, you can look it up as HTML page under support.checkpoint.com

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events