Re: VPN Symantec Gateway Security - Checkpoint Firewall



sk71@xxxxxx wrote:
Hi all.

Can anybody help me to following problem?

I have to connect a Symantec Gateway Security 5400 Series (SGS) to a
Checkpoint firewall. Only some Client's behind the SGS should be able
to connect to the Checkpoint firewall per Checkpoint Client Software.

The Checkpoint Client Software tell me, that the VPN connection works.
But i can't reach any host in the network behind the Checkpoint
Firewall. The Administrator of the Checkpoint Firewall (CPF) told me
that all packages leave the firewall correct, so it seems the SGS is
probably not configure right.

A VPN connection without SGS, only the Checkpoint Client Software, is
working great.
So, the problem is really the SGS and its configuration.

What we do in these types of situations is a one-one NAT for each
internal IP that needs to connect. Most likely your SGS is not
allowing the packets back in. That is why I always test with a dial-up
connection first and then try from behind the firewall.

On the SGS side, setup a one-one NAT for each internal client to
one of your assigned external IP's and allow the necessary ports.

moncho
.



Relevant Pages

  • VPN Symantec Gateway Security - Checkpoint Firewall
    ... Only some Client's behind the SGS should be able ... to connect to the Checkpoint firewall per Checkpoint Client Software. ... The Checkpoint Client Software tell me, ...
    (comp.security.firewalls)
  • Trying to set up an IKE vpn between FreeBSD and Checkpoint FW-1
    ... I am trying to get an IKE vpn going between a 4.2-RELEASE machine (using racoon ... for key exchange) and a Checkpoint firewall. ... I was able to speak with Checkpoint Tech support on this and they did confirm ... I have looked for RFCs to find out which is the accepted standard but could not ...
    (FreeBSD-Security)
  • Trying to set up an IKE vpn between FreeBSD and Checkpoint FW-1
    ... I am trying to get an IKE vpn going between a 4.2-RELEASE machine (using racoon ... for key exchange) and a Checkpoint firewall. ... I was able to speak with Checkpoint Tech support on this and they did confirm ... I have looked for RFCs to find out which is the accepted standard but could not ...
    (FreeBSD-Security)
  • SUMMARY: Checkpoint Blocking Solaris
    ... Subject: Update: Checkpoint Blocking Solaris ... from the DNS server. ... the DNS servers are inside the Checkpoint firewall ...
    (SunManagers)
  • RE: [fw-wiz] Checkpoint
    ... I recall we had similar problems, and eventually, Checkpoint ... and management station at another site. ... > I have query that i have Checkpoint firewall NG software. ... > DO it will wrk or i have to do the necessary change in site also ...
    (Firewall-Wizards)