NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] Réf. : Re: [FW-1] RES: [FW-1] Trouble with NG and SecuRemote



Hi both

I enter your discussion because i already had this kind of problem.

An obvious reminder : if you are in fp2 not to have the encrypt action
means that your policy was created using simplified mode.
This is customized in Policy/global properties/vpn1pro screen.
- As Roelands mentionned to put the extranet object in if via column is
the solution .. using the simplified mode.
- If it still does not work then you might try it it  in traditional mode.

To do this in Fp2 there is no automatic solution, only a manual recreation
of your rules. Do file/new/choose betw simplified or standard. Even rules
copying between simplified and traditionnal do not work.
In Fp3 checkpoint offers conversion tools, to be tested.

Last but not least you should have a look to "what was corrected in fp3"
to see if you are not in a situation created by fp1-2 itself :
http://www.checkpoint.com/support/downloads/docs/firewall1/ng/fp3/Resolved.pdf

HTH

Ivan





"Roelandts, Guy" <[email protected]>
Envoyé par : Mailing list for discussion of Firewall-1
<[email protected]>
10/11/2002 16:49
Veuillez répondre à Mailing list for discussion of Firewall-1


        Pour :  [email protected]
        cc :
        Objet : Re: [FW-1] RES: [FW-1] Trouble with NG and SecuRemote

Fabio,

   As you don't have the client encrypt I suspect you are using the new
 way of configuring the encryptions, you have probably as IF VIA column,
 have you put in that column the remote access community that you have
 created ? Maybe that's the problem.

Met vriendelijke groeten - Bien à vous - Kind regards
Guy ROELANDTS
EMEA GS Internet Expertise Centre - CCSE-NG
Compaq BeLux - now part of the New HP
E-mail : [email protected]
Tel: +32(02)729.77.44 (options 3 - 3 - 1)
Fax: +32(02)729.77.65
==========================================================
This message may contain confidential and/or proprietary information,
and is intended only for the person/entity to whom it was originally
addressed. The content of this message may contain private views and
opinions which do not constitute a formal disclosure or commitment
unless specifically stated. Should you receive this message by mistake
please inform the sender immediately.
==========================================================


-----Original Message-----
From: Fabio Rocha [mailto:[email protected]]
Sent: 05 November 2002 19:25
To: [email protected]
Subject: [FW-1] RES: [FW-1] Trouble with NG and SecuRemote


>May be a typo but the ACTION field should be ClientEncrypt NOT
ClientAuth.

Unfortunately it is not a typo, my firewall doesn?t show "Client Encrypt"
on
the action field, it does only: accept, drop, reject, user auth, client
auth
and session auth.

Why might this be happening? Could be a license problem? My license is as
follows:

CPVP-VSR-1000-NG
CPVP-VEE-U-3DES-MODULE-NG CPVP-VPS-1-NG FW1:5.0:SXL_PPK FW1:5.0:SXL_VPN
FW1:5.0:SXL_FW CPMP-MPU-1-NG CPVP-VEE-U-3DES-MGMT-NG FW1:5.0:DBVR_UNLIMIT

TIA,
Fabio.

--
Ross Bushby
Network Security Consultant
Real Solutions.                                     Tel:Units B&C, Oakcroft Business Centre,  Fax:Oakcroft Rd, Chessington        Web:http://www.realsolutionsuk.com
Surrey, KT9 1RH           E-mail:[email protected]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.