Some problems arise if the private networks on each end of a VPN use the
same private IP scheme.  Such as 192.168.0.0 with 255.255.0.0 in both
places.  If 192.168.x.x is used at the office, then use 172.16.x.x at
home.  At home suggest the smallest subnet --255.255.255.248  or
something.  Only the ends really matter, the ISP in the middle shouldn't
care.
John

ragu nandan wrote:

> Hello
>        We are running Checkpoint 4.1 FW1 (SP2) with
> both IKE and FWZ configured. UDP encapsulation has
> also been implemented on the server.
>  We have a growing number of users (Engineeres) who
> wish to use DSL at home with Checkpoint Securemote
> client. I know there are some issues with Securemote
> and NAT implemented by some DSL providers. So
> a) Is it possible to set a standard so that all users
> use a specific DSL provider and a router. The reason
> is each user wants to buy a home router/modem or some
> software and expect Securemote to work.
> b) This DSL home router should effectively handle all
> NAT issues with minimum tweaking on the client side.
> As many ISP providers supply a dynamic IP thro DHCP,
> securemote should be capable of handling this
> connections.
> We are willing to support 2-3 such home DSL routers. I
> have seen the linksys router and flowpoint routers
> making this list.
> c) Is there a ready docu on how to do it if we choose
> any of the above routers. Are there any gotchas that I
> need to be aware of when using these routers.
> So I would really appreciate any suggestions from you.
> Ragu
>
> __________________________________________________
> Do You Yahoo!?
> Yahoo! Auctions - Buy the things you want at great prices.
> http://auctions.yahoo.com/
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
begin:vcard 
n:Wehrenberg;John Alan
tel;pager:202-994-1800/1266
tel;cell:202-345-2178
tel;fax:202-994-1746
tel;work:202-994-3684
x-mozilla-html:FALSE
org:George Washington University;Information Systems & Services
version:2.1
email;internet:[EMAIL PROTECTED]
title:Network Security Engineer
adr;quoted-printable:;;Rome Hall B-205=0D=0A801 22nd street, N.W.;Washington;DC;20037-1525;USA
fn:John Alan Wehrenberg
end:vcard

Reply via email to