You only must be sure to create correctly the communities and later...just
"copy and paste" the rules from a policy to other.
Once i had a problem with IKE (phase 1) and i solved it putting IKE, ESP and
AH services into "Excluded services" on a community.
But was for a especial case: "a routed VPN between 3 FWs"
good luck...!!!
Saludos,
Mateo Cabrera - Soporte Tecnico
Security Advisor
www.sadvisor.com
-----Mensaje original-----
De: Mailing list for discussion of Firewall-1
[mailto:FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM]En nombre de <Scott
Kavanaugh>
Enviado el: jueves, 23 de septiembre de 2004 10:49
Para: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Asunto: [FW-1] Traditional to Simplified
Good Morning,
This is my first time using this mailing list soo.....
We are currently running NG AI R55 on both the management and gateways. We
are using
traditional mode VPNs with shared secrets. We need to convert to simplified
mode. I would
like to convert one policy at a time on the smaller office gateways and make
sure they work
correctly then convert what I call the core firewall gateway. Does anyone
have any experience
doing this and what the best way to proceed would be? Any gotchas? Thanks.
Scott Kavanaugh
Global Network Operations Center, Americas
Square D / Schneider-Electric
(859) 746-4929
scott.kavanaugh AT us.schneider-electric DOT com
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|