Re: ipsec ISA to Watchguard



thanks
i try , try and try ..

"Leythos" <spam999free@xxxxxxxxxx> escribió en el mensaje
news:MPG.247e385e191701dd989c1d@xxxxxxxxxxxxxxxxxxxxxxx
In article <77hp23F1goqp4U1@xxxxxxxxxxxxxxxxxx>, listas@xxxxxx says...
Phase II , yes pass data


While I'm not doing a IPSec to a ISA server, here is the basic WG
settings I've found that work with all other firewall devices:

Gateway
Use a pre-shared key (not a IPSec FB Cert)
Local Gateway: Your FB IP Address (Public)
Interface External
Remote Gateway: IP Address of other device/fw (Public)
Type: Ip Address
ID: IP Address of other device/fw (Public)
Phase 1
Mode - Main Fall Back to Aggressive
X Nat Traversal
X IKE Keep-Alive
SHA1-3DES, DH 1

BO Tunnel
Address Local ANY
Remote (IP Subnet of LAN side)
Phase II
- PFS (not enabled)
SA Settings (unchecked - default)
IPSec Proposals ESP-3DES-SHA1

This will get the tunnel, but you need a rule to allow traffic between
your LAN and the remote LAN.


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)


.



Relevant Pages

  • Re: IIS IpSec
    ... >then try browse from remote in the same ... >your LAN, working ?? ... >> production IIS Server and I can browse websites just ... >> with the same definitions in my IPSec. ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS IpSec
    ... then try browse from remote in the same ... your LAN, working ?? ... > with the same definitions in my IPSec. ... >>> UDP ports that a IIS Server needs to run? ...
    (microsoft.public.inetserver.iis.security)
  • Re: ipsec ISA to Watchguard
    ... While I'm not doing a IPSec to a ISA server, ... IP Address of other device/fw (Public) ... Remote (IP Subnet of LAN side) ... SA Settings ...
    (comp.security.firewalls)
  • Re: RDP session over Internet logging off
    ... I look all over the Terminal Services Manager and couldn't find ... there doesn't seem to be the same timeout settings when on the LAN. ... I remote into the server from the LAN, I don't think I ever get kicked ...
    (microsoft.public.windows.server.general)
  • [fw-wiz] Advice sought: IPSEC 3DES VPN config on Fedora Core 3
    ... Hardware has been Cisco 837-K9 routers at the remote sites and depending ... Assuming that the FC3 box is up-to-date what is the best way to configure ... Googling for "IPSEC Linux HOWTO" results in conflicting and confusing ... access-list 101 permit ahp host 193.82.1.2 host 82.1.2.3 ...
    (Firewall-Wizards)

Loading