Firewall-1

[FW-1] Spoofing problem ?

Subject: [FW-1] Spoofing problem ?
From: Patrick Marquetecken <patrick.marquetecken AT PANDORA DOT BE>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 30 Aug 2005 16:24:44 +0200
Hi,

Several machine's can't connect if i do a ping i get following error:
message_info: ICMP reply does not match a previous request

The problem is that normal a machine goes true a openvpn tunnel, all the
machines have a static route direct to the openvpn tunnels, de default
dateway  on the machines are the firewalls and the firewall have a static
route to the openvpn tunnel.
If i get following senario i have a problem:

ping to goes:
client -> openvpn -> openvpn -> client
and then for the answer
client -> firewall -> ...end here  (normal openvpn -> openvpn -> client)

in the  networktopology i got the openvpn ranges, the both client network
ranges.

What i'm a missing ?

TIA
Patrick


-- 
This is Unix-Land. In quiet nights, you can hear the Windows machines reboot.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>
  • [FW-1] Spoofing problem ?, Patrick Marquetecken <=