Firewall-1

[FW-1] Configuring ClientLess VPN makes access to HTTPs sites fail

Subject: [FW-1] Configuring ClientLess VPN makes access to HTTPs sites fail
From: Antonio Costa <acosta AT BR.ODEBRECHT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 5 Oct 2004 13:26:35 -0300
Hi all,

 I'm implementing Clientless VPN in a SPLAT R55 envioment with one
 management and two inspection modules with ClusterXL.

 The procedure i did followed all instructions mentioned at the following
SKs:
        Configuring User Authentication, Clientless VPN, and Outlook Web Access
        sk26159

        How to set up Clientless VPN for ICA Certificate users in VPN-1 /
FireWall-1 NG FP3
        sk14246

        How to configure Clientless VPN
        sk21870

 If i create a different service called VPN_ClientLess at TCP/443 and set
 HTTP as its type in advanced service properties, the minute i install the
rules
 every HTTPs traffic starts to fail.

 Note that "match of any" is unchecked and i'm using static NAT to the
webserver node defined.
 Only internal traffic as https to the http server really works...
 no incoming https->http traffic could got in.


 Any1 could give me a hand ?




[]'S

--
 Antonio Costa
 Odebrecht Engenharia e Construcao
 Analista de Redes e Seguranca
 CCNA/CCSE/MCSE/LinuxAdmin

 Atencao - de 26/07 a 17/12/2004 estarei no
 Esc. de Botafogo no Rio de Janeiro
 Tel.: +55-21-2559-3020/3000
 Fax.: +55-21-2559-3056

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>