Hi,

It seems that if I create a single site-to-site encrypt rule from a
group (containing multiple networks, VLANs) and to a single external
private network such as:

Source:         Destination:    Service:        Action:
Group_A         Network_B               Any             Encrypt
Network_B               Group_A

NG FP3 HF2 interprets this as try to encrypt among the different VLANs
within Group_A as well as encrypt between Network_B and Group_A.  The
problem is all the networks in Group_A are in my LAN, so obviously they
shouldn't be encrypted.  I only want traffic from Group_A (my VLANs) to
Network_B (external private LAN) to be encrypted.

What's the proper way to create a rule for this?  Should I be creating 2
groups?

thanks,
Chris

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to