NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] VPN setup problems



You can use IKE instead of FWZ as the encryption scheme. With IKE, you won't
need to accept control connections. Using IKE will also provide stronger
privacy protection.

Alex Malin

-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: Wednesday, December 12, 2001 3:12 PM
To: [email protected]
Subject: [FW-1] VPN setup problems


Hi,

I am running SBFC2.0.35sp5, checkpoint 4.1sp5-rdp-hotfix on a solaris
box. Now I have setup a securemote VPN. However this only works as long
as "Accept VPN-1 FW-1 Control Connections" in the properties tab is
enabled. Anybody running a VPN without that setup successfully? When the
box is unchecked the node itself not the cluster IP replies to IKE
request, so reply packets are dropped by the firewall as those are not
in the state table.

I've built me rulebase according to the implied rules which I really
want to enable and there aren't any drops/rejects in the logviewer
either.

I don't want to enable above property as RDP is enabled by default and
this protocol has had quite a few errors in the past.

Any help/ hint/ comment is really appreciated.

Regards,
Egonle

--




__________________________________________________________________
Your favorite stores, helpful shopping tools and great gift ideas.
Experience the convenience of buying online with Shop@Netscape!
http://shopnow.netscape.com/

Get your own FREE, personal Netscape Mail account today at
http://webmail.netscape.com/

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[email protected]
=================================================

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[email protected]
=================================================

=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
If you have any questions on how to change your
subscription options, email Ron Alcatraz at:
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.