 |
msmobiles.com/f dicussions about Microsoft Smartphone and Pocket PC phone
|
| View previous topic :: View next topic |
| Author |
Message |
msmobiles.com_robot
Joined: 23 Mar 2004 Posts: 16777215
|
Posted: Mon Nov 20, 2006 11:10 pm Post subject: SecureClient Mobile - a VPN for Windows Mobile - released by Check Point |
|
|
If you are in need to connect securely to your corporate network from Internet, VPN is always the answer. Thanks to VPN your mobile device appears in local network and can see all computers - even though it may loca...
Read more at http://www.msmobiles.com/news.php/5781.html |
|
| Back to top |
|
 |
VOODOOS!L

Joined: 23 Feb 2005 Posts: 38
|
Posted: Tue Nov 21, 2006 4:00 pm Post subject: |
|
|
anybody got a working version for Qtek9100?
installation went successfully, but gives an error when starting up  |
|
| Back to top |
|
 |
netneb
Joined: 21 Nov 2006 Posts: 1
|
Posted: Tue Nov 21, 2006 6:24 pm Post subject: |
|
|
I tried to download the package from www.checkpoint.com. Logged in with an account I created several years ago, but I don't have enough rights to get SecureClient Mobile. I want to install, test and use it on my HTC TyTN.
I've read somewhere on Checkpoint's site, the Qtek 9100 (and also my device) is "not supported". Well, this version of SecureClient is compatible with WM5. So it *should work*. But I can't check it. |
|
| Back to top |
|
 |
RedRicKnighT
Joined: 06 Jun 2005 Posts: 11 Location: Bratislava.SK
|
Posted: Wed Nov 22, 2006 8:20 am Post subject: So... |
|
|
From the release notes:
Supported Devices
Any Windows Mobile device that is a PocketPC Phone edition with versions 2003,
2003 SE or 5.0 is supported.
The following devices have also been tested and proved working.
• HP/Compaq iPAQ Pocket PC 2003 - series 4150,4350,3950,5450, 5550,
2210,6340
• Dell AXIM X5 Pocket PC 2003
• HP/Compaq iPAQ Pocket PC 2003 SE - series 4700, hx2x00
• HTC Himalaya (XDA II, MDA II, Qtek 2020, i-Mate, Orange SPV1000)
• HTC Blue Angel (XDA III, MDA III, Qtek 9090, i-Mate 2K, Sprint PPC-660, Verizon
XV6600, Cingular SX66)
• HTC Magician (Dopod 818, i-mate JAM, O2 Xda mini, Qtek 5100, MDA Compact)
• HTC Universal (O2 Exec, i-Mate JasJar, Orange M5000, MDA IV)
• HTC Wizard/Apache (Sprint PPC6700, Orange SPV M3000a, T-Mobile MDA Vario,
i-mate K-Jam)
• HTC TyTN
• ETEN M600
• Dell AXIM X51v
• Symbol MC70
• Motorola HC700
• Intermec 700
• Treo 700w, 700wx, 700v
Since QTek 9100 is HTC Wizard, it is officially supported.
As far as error goes, my guess is, that you have installed it onto memory card. See 2.
1. When working with certificates authentication, make sure there is only one valid
certificate for the relevant gateway in the CAPI store. In case more than one such
certificate exists, the first one is used without prompting the client to choose which
certificate to use (as done by Internet Explorer).
2. Installing the client to a storage card is not supported.
3. On some devices, an error message with the AcquireCredentialsHandle is
mentioned. In most cases this issue is resolved by quitting the client and restarting
it. In some cases a soft-reset is required.
4. Connecting through a proxy that requires digest authentication is not supported.
NTLM authentication is also not supported.
5. On some devices, the routing table is not instantly cleared upon disconnect. This
may cause some applications to fail to connect to the internet for a few seconds
after the client has disconnected. It can take up to 30 seconds for the table to
clear.
6. On some Windows Mobile 5.0 devices when connecting to the gateway over
ActiveSync (used as network interface) some TCP connections, targeted to
resources behind the gateway, do not open over the tunnel, resulting with a
timeout.
7. The flag neo_block_conns_on_erase_passwords flag is not implemented.
8. While the client is installed and not necessarily connected, the device battery life
shortens.
9. When installing the client on Windows Mobile 5.0 PPC, a warning message is
issued stating the application is not signed.
The reason is that the same installation CAB can be installed on PPC 2003, an
operating system that does not support signed CAB files.
10. Certificate enrollment (CheckPoint CA), a feature that is implemented on both
SecureClient and SNX is not supported on this client release. When "Certificate
with enrollment" is selected in SmartDashboard and the user does not have a valid
certificate in its CAPI store, the result is that the user receives an error message.
11. When the client is installed but not running on a Windows Mobile 5.0 device,
ActiveSync is disabled. To over come this, start the client, then start the
ActiveSync. Since the client is not running, a change in the fireWall policy required
for the ActiveSync protocol to run cannot be applied.
12. When both neo_always_connected is set to true and disconnect_in_activesync is
set to true the client goes into an infinite loop resulting with screen flickering and
a client crash.
13. On some devices the client drivers do not load if device was started cradled
(connected to ActiveSync cable/cradle) or after installation of some problematic
software. The meaning of this is that the client firewall is not running and the client
cannot connect. A clear error balloon is displayed to the user in this case. To
overcome this problem un-cradle the device then restart it; uninstall the
problematic software. For more information, see sk#31837.
14. The neo_enable_automatic_policy_update and
neo_automatic_policy_update_frequency flags are not implemented in this
release. neo_policy_expire is in place.
15. On some devices the client's Today Item stops responding after some use. Uncheck
the "Show Today Item" checkbox in the client Options dialog to remove the Today
Item from the screen.
16. The device issues DNS queries on both the physical interface and the virtual
interface resulting with a potential exposure of servers names and IP addresses. To
overcome this set the flag neo_allow_clear_while_disconnected to false.
17.MSI installer does not enforce that upgrading should only be done to a higher build
number. On the device, when the CAB file is installed this enforcement does take
place.
18. The flags neo_disconnect_when_idle and neo_disconnect_when_idle_timeout are
not implemented in this release.
19. On some devices, the routing table is not instantly cleared upon disconnect. This
may cause some applications to fail to connect to the internet for a few seconds
after the client has disconnected. It can take up to 30 seconds for the table to
clear.
20. Connecting to patched and unpatched servers alternately is not supported.
21. The flag neo_request _policy_update is not operative (has no effect).
22. The flag neo_block_conns_on_erase_passwords flag is not implemented.
23. The client does not support Connectra's Network Extender Application Mode. When
setting Connectra to Application Mode only client connection fail with the error
message "authentication failure (201)".
RRK |
|
| Back to top |
|
 |
VOODOOS!L

Joined: 23 Feb 2005 Posts: 38
|
Posted: Wed Nov 22, 2006 8:54 am Post subject: |
|
|
I tried the application after installing it on the device itself, instead of storage card. But still, after starting the SecureClient, I get an 'Internal error' and the application closes immediately.
Which setup did you use to install the application?
I tried with 'SecureClient-PPC2K3-149.zip'
Thanks! |
|
| Back to top |
|
 |
RedRicKnighT
Joined: 06 Jun 2005 Posts: 11 Location: Bratislava.SK
|
Posted: Wed Nov 22, 2006 9:10 am Post subject: |
|
|
| VOODOOS!L wrote: | I tried the application after installing it on the device itself, instead of storage card. But still, after starting the SecureClient, I get an 'Internal error' and the application closes immediately.
Which setup did you use to install the application?
I tried with 'SecureClient-PPC2K3-149.zip'
Thanks! |
I did not But I have already downloaded Integrity-M_Setup_611000148.cab
Our checkpoint gateway does not have needed patches installed.
BTW I am afraid, that many users will try this to access all kinds of VPNs. They will fail.
This client only works with Checkpoint gateways, that are patched to the newest versions. You need at least NGX R60 HFA04, or maybe Connectra R62. And it needs to be properly licensed.
Very few companies have those, and I do not know of any individual having it at home, since it does cost quite much.
RRK |
|
| Back to top |
|
 |
VOODOOS!L

Joined: 23 Feb 2005 Posts: 38
|
Posted: Wed Nov 22, 2006 11:08 am Post subject: |
|
|
| RedRicKnighT wrote: | | VOODOOS!L wrote: | I tried the application after installing it on the device itself, instead of storage card. But still, after starting the SecureClient, I get an 'Internal error' and the application closes immediately.
Which setup did you use to install the application?
I tried with 'SecureClient-PPC2K3-149.zip'
Thanks! |
I did not But I have already downloaded Integrity-M_Setup_611000148.cab
Our checkpoint gateway does not have needed patches installed.
BTW I am afraid, that many users will try this to access all kinds of VPNs. They will fail.
This client only works with Checkpoint gateways, that are patched to the newest versions. You need at least NGX R60 HFA04, or maybe Connectra R62. And it needs to be properly licensed.
Very few companies have those, and I do not know of any individual having it at home, since it does cost quite much.
RRK |
i suppose my company supports it, I need to use the secureclient on my notebook...
where did you get the 'Integrity-M_Setup_611000148.cab'?
is that the new windows mobile version?
maybe, you could upload it (eg to rapidshare.com free) since I can't find the WM5 edition anywhere, and the online request form is not working correctly on the CheckPoint site.
Thanks anyway!! |
|
| Back to top |
|
 |
RedRicKnighT
Joined: 06 Jun 2005 Posts: 11 Location: Bratislava.SK
|
Posted: Wed Nov 22, 2006 11:15 am Post subject: |
|
|
| VOODOOS!L wrote: |
i suppose my company supports it, I need to use the secureclient on my notebook...
where did you get the 'Integrity-M_Setup_611000148.cab'?
is that the new windows mobile version?
maybe, you could upload it (eg to rapidshare.com free) since I can't find the WM5 edition anywhere, and the online request form is not working correctly on the CheckPoint site.
Thanks anyway!! |
I got it from checkpoint site without any problems.
The cab file is installable on WM5 and WM2003 devices.
There are separate licenses needed for SecureClient and SecureClient Mobile on VPN gateway. Ask your Checkpoint administrator.
RRK |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|