- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Guys,
Again converting legacy policies to R80.10; here is one more issue would like to discuss. Previously I had legacy user access Remote Access VPN Solution [EPM].
Then edited the policy and ticked the Application Blade.
When tried installing policy it threw an error about legacy user access group which was used for Remote VPN. Hence I created access role and added those groups in the rule.
Now policy installation was successful and even users were getting connected however one issue I faced was even though ports were allowed in the same rule. Traffic was dropping for Office mode client IPs to destination IPs which were present in the rule and it was dropping at the clean up rule.
Any clue why? Then I again reverted the changes and it started working fine.
Like
Rule#56
Source - RDPusers@Any
Dest - RDP_10.10.10.10
Service - TCP_3389
Action - Accept
Rule#80
Any
Any
Drop
So traffic was dropping at Rule#80 when Rule#56 was converted to
Source - Access_Role_RDPUsers
Dest - RDP_10.10.10.10
Service - TCP_3389
Action - Accept
If you had a VPN community in the rule with access roles, this may have caused the drops, provided you were using "Unified Access Policy".
That is applicable to end point VPN as well? Or only for mobile access policy? Yes I have community in the rule base.
What should be done in that case?
My understanding is that "Mobile Access Policy" is covering all remote access means and is run either in Legacy or Inline modes.
This is the example of the policy I was using in one of my labs with Mobile Access layer:
With Access Roles configured according to your client of preference and the VPN column set to Any.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY