How do I change firewall settings modified by VPN server?

(This actually happened while I was running Lion, but seems to be the same problem under Mountain Lion)
I installed Check Point Software Technologies Ltd. Endpoint Security VPN for Mac E75 VPN client on my iMac to access my employer's network.  It worked, but after I logged onto my employer's network, I lost contact to both my Time Capsule and Airport Express (Airport Utility stops "seeing" them, even though I am still connected over wi-fi to the internet through the airport router in the Time Capsule), and iTunes stopped "seeing" my iPad and iPhone.
I looked on Check Point's support pages and saw this "Known Limitation":
Issue ID:  00885275
After Endpoint Security VPN is installed and a client is connected to the gateway, automatic sync with Time Capsule and iPhone Wi-Fi sync might not work correctly.
This can happen because of a restrictive Desktop Policy.
To resolve this issue, allow these services in the "Inbound rules" of the Desktop Policy:
SSDP: UDP, port 1900.
mDns: UDP, port 5353.
Further research in the Endpoint Security VPN for Mac E75 Administration Guide told me this about "Desktop Policy":
The Desktop Firewall
Endpoint Security VPN enforces a Desktop Security Policy on remote clients. You define the Desktop Security Policy in a Rule Base. Rules can be assigned to specific user groups, to customize a policy for different needs.
Important - Before you begin to create a Desktop Security Policy, you must enable the Policy Server feature on the gateway.
Endpoint Security VPN downloads the first policy from the gateway. It looks for and downloads new policies every time it connects or on re-authentication.
When Endpoint Security VPN makes a VPN connection, it connects to the gateway and downloads its policy. Endpoint Security VPN enforces the policy: accepts, encrypts, or drops connections, depending on their source, destination, and service.
So (I think) what happened is when I logged on to my employer's network, it re-configured my firewall to limit my network connections resulting in the above-described problems.
Logging out did not change anything.  Uninstalling the VPN client did not change anything. It looks like the changes "enforced" by the VPN client are persistent, and can only be changed "manually."
I doubt I will be able to prevail upon my employer to change its desktop policy.  So I'm ready to bail on using the VPN client, but how do I reverse the changes my employer's "desktop policy" made?
The System Preferences Firewall options seem kind of high level.  I would note that iTunes looks like it is open to all connections.
Thoughts?  HELP.

It is not something I have played with.. but I would turn off the Mac's firewall and see if that fixed the problem.. the firewall of the Mac is helping your security.. but the main security is actually the NAT router in the TC. It is extremely difficult to break NAT routing.. It is effectively a firewall itself. So turning off the firewall in the Mac is not a biggie. The reason I want you to do that even if just for a few minutes.. and perhaps turn it off and reboot the computer to make sure the rules have stopped being applied.. is to see if the firewall is actually the culprit.
What I am reading from what you have posted is the vpn client itself is the software blocking connections. And I doubt a third party software would change rules to the internal firewall.. but i am guessing.
Once you have tested it.. if the firewall off fixes it.. then you will need to hunt around.. perhaps in a TM backup for the actual file that is altered that contains the rules.. I have not looked.. and don't use firewall on the end client anyway as I have a firewall rated router.
If the firewall off does not fix the problem.. which is what I suspect. Did you use the uninstall software correctly and did it give any error messages??
Go to the activity monitor and check all the running processes.. anything there that is named after the vpn.. try to quit. See if you can stop the process.. If the issue is major.. and the process won't quit see if the Checkpoint support can help or google their knowledge base for info on how to get back to normal operations.

Similar Messages

Maybe you are looking for

  • How to use standard program RSCP_CONVERT_FILE?

    Hi experts, I got a requirement to convert the file format from non_unicode to unicode. For that I am using the standard program RSCP_CONVERT_FILE. Its working fine for Local PC. But am getting problem while reading file on Application server. In sel

  • Calling mysql stored procedure having insert sql commands within cftransaction is not getting rolled back

    Hi, cftransaction is working perfectly when all the insert updates are called by cfqquery. But when there is a mysql stored procedure call with in cftrnsaction and that mysql stored procedure is having many inserts and updates, cftransaction is not a

  • Problem scrolling using property nodes

    What Im trying to do is a "fake scroll bar" using numeric controls and the VI Property FP Origin for the same vi where the numeric controls are. The problem is that when the vi is running and I use the scroll bar the controls also move and is a mess.

  • Quizzes - More than 1 question per screen

    Hi There, I am new to capptivate this week and am wanting to know if anyone knows how to place more than one quiz question on a single screen? Many thanks in advance Ali

  • Illustrator CS4 will not install

    Win 7 64 bit, Photoshop CS4 installed.  Try to install Illustrator CS4 and runs into a problem updating Photoshop and stops the install.