[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] VPN-1 and SecuRemote



Title: RE: [FW1] VPN-1 and SecuRemote
I didn't catch the beginning of this thread but let me guess;  you are using SR 4165 and Windows 9x???  If so try adjusting the MTU size for dialup networking.  From version 4157 to 4165, Checkpoint changed the size of first packet of the Quick Mode (phase 2) from ~540 to ~780.  By default the MTU of the dial up adaptor on 98 machines is ~576 therefore the packet gets fragmented and is probably being dropped by your router & / or the firewall.

For modem adapters on Windows 98 and Windows 95 with DUN 1.3:

1) Use Control Panel => Network to view the network properties.

2) In the Adapters tab, double-click on the modem adapter

3) In the <network_adapter_name> window, open the Advanced tab

4) Click on the IP packet size and choose Large packet size

5) Reboot

 

I hope this helps!

 

-Will

-----Original Message-----
From: [email protected] [mailto:[email protected]]On Behalf Of Michael Drannikov
Sent: Tuesday, January 30, 2001 3:13 PM
To: 'Iztok Umek'
Cc: '[email protected]'
Subject: RE: [FW1] VPN-1 and SecuRemote

I'll bet if you take look at your routing table on the client netstat -rn you'll see the answer.

Michael

-----Original Message-----
From: Iztok Umek [mailto:[email protected]]
Sent: Tuesday, January 30, 2001 11:57 AM
To: [email protected]
Subject: [FW1] VPN-1 and SecuRemote



I've done a little debuging of my connection.

When I have laptop with NIC sitting between my FW and router I can get
autenticated and use VPN. I get ISAKMP packets sent to and receive from
fw. On the other hand if I use dial-up connection I can get topology
downloaded and client even starts sending ISAKMP to the FW (I see the
packets with EtherPeek). But FW does not send any ISAKMP packets back
like it does when I am in NIC directly in front of FW itself.

Any hints on how to tackle this?

Regards,
        Iztok


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================