RE: [fw-wiz] Cisco 506E and CP NG VPN Problems

From: Melson, Paul (PMelson_at_sequoianet.com)
Date: 08/11/03

  • Next message: Crissup, John (MBNP is): "[fw-wiz] PIX 6.3.2 Upgrade?"
    To: "Jorge Valenzuela S." <jvalen@alefdata.cl>
    Date: Mon, 11 Aug 2003 09:49:22 -0400
    
    

    I don't believe that the problem is with the PIX configuration. More likely, the Check Point firewall has a rule for the VPN tunnel that looks something like this:

    SRC DST IF VIA SERVICE ACTION
    [your_net] [his_net] [vpn_comm] * Any accept

    The Check Point firewall needs another rule that switches the source and destination objects. For him to be able to initiate a VPN tunnel to your PIX, his firewall needs to have a rule where his network is the source and yours is the destination that is "IF VIA" the same VPN extranet community as the existing rule. For example:

    SRC DST IF VIA SERVICE ACTION
    [his_net] [your_net] [vpn_comm] * Any accept

    Hope that helps!

    PaulM

    > -----Original Message-----
    > We have a CISCO 506E to raise a VPN to our customer Cehckpoint NG FW,
    > but after severa hours of inactivity if our customer try to conect to
    > our server through the VPN he cant see our server, but if we ping to his
    > workstation from our server we can see hiw workstation, after that he
    > also can se our server an works normally....until he disconect for
    > several hours.
    >
    > any idea ?
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Crissup, John (MBNP is): "[fw-wiz] PIX 6.3.2 Upgrade?"

    Relevant Pages

    • Re: More on Remote Desktop
      ... Chances are good, though, that he's already got VPN capabilities on his ... firewall to do it for $100. ... > server at home...or purchase additional/new hardware... ... >> my firewall makes the PPPoE connection to my ADSL ISP. ...
      (microsoft.public.windowsxp.network_web)
    • Re: More on Remote Desktop
      ... You realize the Remote Desktop data stream is encrypted the same as a PPTP VPN link... ... Unless of course the original poster wants to implement an L2TP/IPSec VPN server at home...or ... > firewall to get between your clients and server on your own LAN. ... > setup so that my firewall makes the PPPoE connection to my ADSL ISP. ...
      (microsoft.public.windowsxp.network_web)
    • Re: VPN Firewall for new webserver
      ... > I'm setting up a webserver at a colocation and I need to put a VPN ... You're not going to get a quality firewall for that amount, ... and D-Link makes a DI-804HV unit ... users access to the SQL server, let them do it through a VPN session. ...
      (comp.security.firewalls)
    • Re: Cant logon to computer in SBS Domain..
      ... Does the user can access and log on to the Remote Web Workplace? ... Whether you can connect and log on to the server desktop through RWW? ... On the Firewall page, ensure that Enable firewall is selected. ... About External Firewall VPN ...
      (microsoft.public.windows.server.sbs)
    • Re: xp sp2 an 2003er domäne
      ... >Der Angreifer ist nicht nur eingedrungen, ... >> Also du schlägst vor dass ich da ne Firewall vor klemm. ... bzw. dann heisst die Lösung VPN. ... >stehen können frei mit dem Server kommunizieren. ...
      (microsoft.public.de.german.windows.server.networking)