This may not be your solution, however....
We had problems with users being authenticated, but not being able to go
anywhere.
The solution was to configure their TCP/IP connection to use our DNS servers
(listed after their ISPs DNS servers) and to append the domain
(domainname.com)
It fixed our connection problems.
Baker
-----Original Message-----
From: Trevor Dixon [mailto:TrevorD AT METAPHORIX.CO DOT UK]
Sent: Friday, October 31, 2003 8:53 AM
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: Re: [FW-1] Can not connect through VPN!
Is there anything I need to configure on the gateway module?
-----Original Message-----
From: O'Flynn, Derek [mailto:DOFlyn AT LSUHSC DOT EDU]
Sent: 30 October 2003 16:25
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: Re: [FW-1] Can not connect through VPN!
Could you describe the subnets involved?
I've seen problems if you are originating from a NAT network, 192.168.1.x
and your inside network is 192.168.1.x, it will do similar to what you are
describing, BUT you usually see logs under Tracker for VPN showing the
sessions.
Do you have your encryption domain defined? If this is not set, then
SecuRemote will not know for what networks it needs to encrypt. Set the
encryption domain and then update your SecuRemote site.
Derek
-----Original Message-----
From: Trevor Dixon [mailto:TrevorD AT METAPHORIX.CO DOT UK]
Sent: Thursday, October 30, 2003 9:29 AM
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: [FW-1] Can not connect through VPN!
Importance: High
Hi there FW-1 gurus!
I have a problem that needs an expert to solve.
I have configured an Intrusion PDS 2105 box running pilot 2.4 (7), FW-1 &
VPN-1 as a Firewall gateway.
Installed on a Windows 2000 server is Check Point's Small Office 4.1 Policy
editor used to configure the polcies.
I am trying to setup a VPN using SecureRemote. The SecureRemote client
authenticates but you are unable to ping
or connect to any of the resources on the host network. The logs show when
the encrypted client connects but nothing else.
Any ideas on what's missing from the configuration?
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|