Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WhOPP
Participant

domain-udp Decrypted in community RemoteAccess

Hi,

we have about 100 VPN users. Some use CP mobile, some SecureRemote.

Only one user have some problem. On his site, he doesn't have any problems. But in log file, there is record every 20-40sec. Copy is down below.

I did try to fresh install client and also tries his credentials on new PC, but problem remains.

Why is his computer try to connect to DC every few seconds? He only use VPN for RDP, but even if he only establishes VPN without RDP connection, logs are full with same message as copy of log bellow.

Did try with win10 and win11. All other users doesn't create logs like one bellow

 

 

 


Interface Direction: inbound

Id Generated By Indexer: false
First: true
Sequencenum: 1
Source Zone: External
Destination Zone: Internal
Service ID: domain-udp
Source: 10.18.252.27
Source Port: 58782
Destination: 10.18.205.35
Destination Port: 53
IP Protocol: 17
Scheme: IKE
Methods: ESP: 3DES + SHA1
VPN Peer Gateway: 10.18.252.27
Community: RemoteAccess
VPN Feature: VPN
Action: Decrypt
Type: Connection
Blade: VPN
Service: UDP/53
Product Family: Access
Logid: 0
Access Rule Name: VPN Support
Description: Decrypted in community RemoteAccess

0 Kudos
4 Replies
the_rock
Legend
Legend

If I were you, since you say its just 1 single user, I would maybe have them delete/re-create VPN site, if that fails, have them reinstall the vpn client (maybe try latest one, E87.30)

Cheers,

Andy

0 Kudos
WhOPP
Participant

Hi, thanks for replay

I did delete user and create new one with new certificate. Also reinstalled client on his PC and also try with new clean VM but results are same.

All users use same client

https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/htm...

FW is R81.10

 

0 Kudos
the_rock
Legend
Legend

Maybe try newest VPN client to see if it makes any difference. Only other reason I can think of would be maybe some 3rd party software possibly causing this. Other than that, maybe engage TAC, but not real sure how much they can do either, considering its definitely not the FW issue.

Andy

0 Kudos
_Val_
Admin
Admin

The client is dowing DNS requests. I guess it is perfectly normal.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events