NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] Can't reach securemote clients from encryption-domain.



Hi list,

      I have recently configured a VPN gateway-cluster with two nodes,
      using Firewall 1 v41 SP3 3DES and StoneBeat Fullcluster 2, b2035 SP2a

      I am using Securemote Pool NAT and udp-encapsulation for NATed
      clients.

      Half of the pool is routed to each node via securemote filter.conf

      I can telnet my linux box inside the encryption domain from my
      securemote client, but i CAN NOT telnet the securemote client from
      the linux box. I don't get even the "connection refused".

      If I do the telnet to the pool IP of the client, the log says OK
      accept and "encrypt" and I can see the packets going to the client on
      my fw external interface, right to the client, but they are ignored.

      The packets from the client have the virtual IP of the gateway
      cluster as destination address, but the cluster answer from the
      physical adress of one of the nodes, is this normal?

      any idea?

      thanks.

          Raúl.



La información incluida en el presente correo electrónico es CONFIDENCIAL,
siendo para el uso exclusivo del destinatario arriba mencionado. Si usted
lee este mensaje y no es el destinatario señalado, el empleado o el agente
responsable de entregar el mensaje al destinatario, o ha recibido esta
comunicación por error, le informamos que está totalmente prohibida
cualquier divulgación, distribución o reproducción de esta comunicación, y
le rogamos que nos lo notifique, nos devuelva el mensaje original a la
dirección arriba mencionada y borre el mensaje.
Gracias.



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.