OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
RE: [ISSForum] Problems with adaptive profiles for RS Desktop

From: Andrew Plato (aplatoanitian.com)
Date: Mon Feb 02 2004 - 11:19:43 CST


I have clients with trouble using the Cisco, WatchGuard, and Checkpoint
clients.

Just to note, I have tried:

- Using the external (public) IP address of the VPN
concentrator/firewall
- Using the virtual IP range.
- Using the virtual IP range and making sure its NOT part of the corpnet
range

None of these options work. The agent stays in the default setting.

___________________________________
Andrew Plato, CISSP
President / Principal Consultant
Anitian Enterprise Security
  
503-644-5656 Office
503-214-8069 Fax
503-201-0821 Mobile
www.anitian.com
___________________________________
   

> -----Original Message-----
> From: Corman, Joshua D. (ISS New Hampshire) [mailto:jcormaniss.net]
> Sent: Monday, February 02, 2004 6:44 AM
> To: Andrew Plato
> Subject: RE: [ISSForum] Problems with adaptive profiles for RS Desktop
>
> I may be able to help.
>
> Which VPN Client?
>
>
> -----Original Message-----
> From: issforum-adminatla-mm1.iss.net On Behalf Of Andrew Plato
> Sent: Saturday, January 31, 2004 4:07 PM
> To: issforumatla-mm1.iss.net
> Subject: [ISSForum] Problems with adaptive profiles for RS Desktop
>
>
> I've been working with ISS support on this issue but they do
> not have a solution yet. I have numerous furious customers so
> I thought I'd see if anybody else is experincing these issues.
>
> I have a whole collection of customers who cannot get
> Adaptive Profiles working. The problem is the VPN group.
>
> The documentation says to use the external IP of the VPN
> concetrator/firewall for the VPN adresses for the VPN
> adaptive profile.
> But when we use this, it doesn't work. Agents on VPN
> connections remain in default.
>
> So, we tried putting the Virtual IP range assigned to the VPN
> clients into the VPN rules. Nothing, remains in default.
>
> What's weird, is that when we put the virtual range into
> corpnet - the agent switches into corpnet just fine.
>
> Has anybody seen this behavior. Do you have ANY suggestions?
>
> Thanks.
>
> ___________________________________
> Andrew Plato, CISSP
> President/Principal Consultant
> Anitian Enterprise Security
>
> 503-644-5656 Office
> 503-214-8069 Fax
> 503-201-0821 Mobile
> www.anitian.com
> ___________________________________
>
> _______________________________________________
> ISSForum mailing list
> ISSForumiss.net
>
> TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to
> https://atla-mm1.iss.net/mailman/listinfo
>
>

_______________________________________________
ISSForum mailing list
ISSForumiss.net

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to https://atla-mm1.iss.net/mailman/listinfo