Bij een klant heb ik volgend probleem:
VPN verbinding valt regelmatig weg, user moet dan wachten tot het VPN logon scherm terug verschijnt en kan na herinloggen terug een tijdje verder werken.
Nu beheren wij niet zelf die VPN (checkpoint) maar wel het zusterbedrijf.
Toen we het probleem voorlegden kregen we volgende uitleg.
-------------------------------
For setting up their VPN connection with the **** Group LAN more and more users are using a router/firewall box at home. This box then has a built-in DHCP server, providing your home pc with an IP address from one of the private ranges.
The **** Group Firewall (with which the VPN is set up) uses this IP address for the communication with your PC.
Now if 2 users have a VPN active at the same time using the same IP address on the PC at home (or another remote location), then the firewall will frees one session in favorite of the other. If then that other session sends traffic it will frees the first one and unfrees the last one to reactivate it. For example we have 2 VPN's: vpnA and vpnB. The remote pc's of vpnA an vpnB have the same internal IP address; for example 10.0.0.2. Traffic in vpnA is working fine. Then traffic is sent over vpnB. As they have the same remote IP address, the firewall will frees (pause) vpnA in favor of vpnB, which becomes active again. These switches are done rather fast and work fine as long as the traffic is not to heavy and there are not to much users with the same remote IP-address. But because companies standardize on internet equipment for home users, we are getting in the situation that more than 2 users have the same remote IP-address at the same time!
When several users start working at the same time they might have problems, because returning packets are send to the wrong sessions and replies are timing out!
To avoid this situation I want to assign as much as possible, a unique IP address to each Pc involved with a secureclient VPN.
PC's that get their IP address from the internet are not impacted, because they get a unique IP address.
.....
Dan nog een hoop blabla over het feit dat alle home users aangepast moeten worden.
----------------
Dit lijkt me een mooie uitleg maar houdt voor mij totaal geen steek.
Want als ik het NAT verhaaltje goed snap, wordt je intern IP address toch vertaalt naar je extern IP address door een extra pakketje rond je IP pakket te zetten?
Dus je gaat toch buiten met je publiek adres? In principe weet de company firewall toch niet af van het ipadres van de client?
Graag jullie commentaar hieromtrent.
VPN verbinding valt regelmatig weg, user moet dan wachten tot het VPN logon scherm terug verschijnt en kan na herinloggen terug een tijdje verder werken.
Nu beheren wij niet zelf die VPN (checkpoint) maar wel het zusterbedrijf.
Toen we het probleem voorlegden kregen we volgende uitleg.
-------------------------------
For setting up their VPN connection with the **** Group LAN more and more users are using a router/firewall box at home. This box then has a built-in DHCP server, providing your home pc with an IP address from one of the private ranges.
The **** Group Firewall (with which the VPN is set up) uses this IP address for the communication with your PC.
Now if 2 users have a VPN active at the same time using the same IP address on the PC at home (or another remote location), then the firewall will frees one session in favorite of the other. If then that other session sends traffic it will frees the first one and unfrees the last one to reactivate it. For example we have 2 VPN's: vpnA and vpnB. The remote pc's of vpnA an vpnB have the same internal IP address; for example 10.0.0.2. Traffic in vpnA is working fine. Then traffic is sent over vpnB. As they have the same remote IP address, the firewall will frees (pause) vpnA in favor of vpnB, which becomes active again. These switches are done rather fast and work fine as long as the traffic is not to heavy and there are not to much users with the same remote IP-address. But because companies standardize on internet equipment for home users, we are getting in the situation that more than 2 users have the same remote IP-address at the same time!
When several users start working at the same time they might have problems, because returning packets are send to the wrong sessions and replies are timing out!
To avoid this situation I want to assign as much as possible, a unique IP address to each Pc involved with a secureclient VPN.
PC's that get their IP address from the internet are not impacted, because they get a unique IP address.
.....
Dan nog een hoop blabla over het feit dat alle home users aangepast moeten worden.
----------------
Dit lijkt me een mooie uitleg maar houdt voor mij totaal geen steek.
Want als ik het NAT verhaaltje goed snap, wordt je intern IP address toch vertaalt naar je extern IP address door een extra pakketje rond je IP pakket te zetten?
Dus je gaat toch buiten met je publiek adres? In principe weet de company firewall toch niet af van het ipadres van de client?
Graag jullie commentaar hieromtrent.