I am not sure about the other person, but our internal is 10.x.x.x and
IP of host is 192.x.x.x

That was my first thought.  I am wondering if it is a routing issue in
our router?  I am frustrated.

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Scott
Friedman
Sent: Thursday, November 20, 2003 2:07 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] CP NG AI Secure Remote Issue


Are you using the same IP/subnet mask on your client that is being Used
anywhere in the Encryption Domain/Topology on the Main Site?

That is usually the main culprit.. Look for any network objects with the
same IP/mask that your using..  Then try changing your Securemote client
to another range

Scott Friedman
Security Engineer - NG CCSE
[EMAIL PROTECTED]
Advanced Network Solutions
1750 S. Telegraph Rd  Suite 100
Bloomfield Hills, MI 48302
(248) 857-5526  x132

www.advnetworks.com


-----Original Message-----
From: David Walker [mailto:[EMAIL PROTECTED]
Sent: Thursday, November 20, 2003 3:40 PM
To: [EMAIL PROTECTED]
Subject: [FW-1] CP NG AI Secure Remote Issue


Group,

I've installed Checkpoint NG with AI.  It has a public IP address and it
is configured for Secure Remote access.  When I connect to the it via
the Secure Remote for the first time, it prompts me for my
username/password, tells me I'm authenticated, displays the certificate,
and downloads the topology.  When I try to access the 1 server within
the encryption domain, I receive ERROR: COMMUNICATION WITH GATEWAY
x.x.x.x HAS FAILED.

When I attempt to update the site within the Secure Remote program, I
recieve the same error.  The logs show the initial logon and topology
download, but nothing else after that.

When doing a tcpdump on the external interface of the firewall, I see
the incoming and outgoing packets from/to Secure Remote client
initially, but again nothing after that.  It's almost like the Secure
Remote client is preventing access.

If I stop Secure Remote on the laptop, I am able to TELNET to the
firewall.

I'm using a laptop with WinXP, latest Secure Remote NG with AI, I've
stop IPSEC services (Checkpoint recommendation).  Have tried via dialup
and direct broadband.

The rule is at the top on my policy.

Any suggestions?

David

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to