- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- keepalive on Endpoint Security
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
keepalive on Endpoint Security
The user upgraded to E88.50 and we are still seeing the issue. ICMP pings from his PC or router to the gateway. Is there some kind of keepalive ping check on Endpoint Security I can have him uncheck? We are trying to figure out what's sending pings back to the remote access gateway (which are dropped) dest-unreach (ICMP). We don't allow ping.
- Labels:
-
Windows
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is enable always connect, but in order for client to be able to check that, it has to be enabled in global properties, under endpoint options. Except in your case, it should say always connected.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, there is and it actually has absolutely zero to do with endpoint version. Its in global properties and its refered to below.
Hope that helps.
Best,
Andy
http://downloads.checkpoint.com/dc/download.htm?ID=60345
To configure tunnel idleness:
1. Connect to the Security Management Server with GuiDBedit.
2. Open the Global Properties > properties > firewall_properties object.
3. Find disconnect_on_idle and these parameters:
• do_not_check_idleness_on_icmp_packets
• do_not_check_idleness_on_these_services - Enter the port numbers for the services that you want to ignore when idleness is checked.
• enable_disconnect_on_idle - to enable the feature
• idle_timeout_in_minutes
4. Save and install the policy.
Btw, there is ping option there you can change, so if user is somewhat savvy, they can always keep pinging say google dns in cmd and tunnel will NEVER time out, though its supposed to say after 60 mins (just as an example)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, that 60345 link isn't opening for me. I'm looking for something to change on the client side actually. Is there a tunnel keep alive check box for example?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is enable always connect, but in order for client to be able to check that, it has to be enabled in global properties, under endpoint options. Except in your case, it should say always connected.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Daniel_Kavan Glad we can help mate. If anything else, just update the thread.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is just RAS VPN Admin guide, you can look it up as HTML page under support.checkpoint.com
