Hi Duncan,
What's the SecureClient log viewer show? I think it would show something
inbound being dropped.
Does the DHCP server update dynamic DNS on behalf of the client or are you
allowing each client to do it directly?
An Office Mode problem with SecureClient not updating the dynamic DNS was
supposed to be corrected in NGX HFA01, in case you didn't know about it.
Ray
From: "Meyers, Duncan" <duncan.meyers AT AU.UNISYS DOT COM>
Reply-To: Mailing list for discussion of Firewall-1
<FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: [FW-1] SecureClient DNS registration
Date: Wed, 23 Nov 2005 12:36:48 +1100
Hi all,
I have a bit of an odd problem that seems to be related to SecureClient
(NGX R60 Build 191 on XP).
When a laptop that has SecureClient installed and a simple desktop policy
active (allow all outbound, drop all inbound) is connected to the company
LAN, it picks up an IP address from the Windows 2003 DHCP server but
doesn't update the active DNS registration so that if you ping the machine
name it, the DNS sever replies with an old address.
The problem goes away immediately if you stop the VPN-1 SecureClient - that
is; the DNS entry is updated.
Any thoughts?
Thanks,
Duncan
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|