Hi Peter,

sorry, no further ideas. That worked reproduceable in my lab environment.
Only thing I was messing around had been the information to enter in the
edge box, the name (object name of the edge in smartcenter) and the
registration code (compareable with OTP of SIC) when enabling smartcenter
management on the unit :-(

Regards
ulli

-----Original Message-----
From: Peter Weyrosta <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Date: Wed, 11 Feb 2004 10:48:25 +0100
Subject: [FW-1] AW: [FW-1] AW: [FW-1] AW: [FW-1] VPN Edge integration with
R55 SmartCenter

> Hi Ulli,
>
> sorry for the incomplete infos, in fact I did the same (even with
> any-any-accept to the management) ...and yes, I removed this rule after
> a few tests :-)
>
> But I found another setting that had in fact an impact on my setup even
> tough it shouldn't from my point of view.
>
> Under Global Properties/VPN there is a check box for "Enable decrypt on
> accept for gateway to gateway traffic (relevant only to policies in
> Traditional Mode)"
>
> My Policy Package is simplified (though converted from traditional). So
> this setting should not affect the behaviour of my policy package. But
> in fact it did. As long as I had this check box checked I got an
> encryption error on the incomming SWTP-SMS packets stating that there
> may be a NAT problem or the Domain ID may be different. As soon as I
> unchecked it, the packets came in fine.
>
> But as said, I can trace the packets coming through to the smartcenter.
> The only thing I can imagine now is, that they are in fact encrypted
> and doesn't get decrypted at the module because of this setting. So
> that the smartcenter gets the packet, but cannot read it, since it's
> contents are encrypted and doesn't make sense to it.
>
> regards
> Peter
>
> -----Urspr�ngliche Nachricht-----
> Von: Mailing list for discussion of Firewall-1
> [mailto:[EMAIL PROTECTED] Im Auftrag von
> fw-1.group
> Gesendet: Mittwoch, 11. Februar 2004 07:28
> An: [EMAIL PROTECTED]
> Betreff: Re: [FW-1] AW: [FW-1] AW: [FW-1] VPN Edge integration with R55
> SmartCenter
>
> Hi Peter,
> On Feb 11, 2004, at 12:15 AM, Peter Weyrosta wrote:
>
> > hi,
> >
> > hfa01 is installed on both management and module.
> > nat should not be the problem, since ping is no problem in both
> > directions and tracroute shows that the connection is routed through
> > the tunnel.
> >
> > we tried two ways:
> >
> > first) edgebox tries to register to private ip of management.
> > second) static nat of management to outside. edgebox tries to
> register
> > to public (nated) ip address of management.
>
> got this 2nd way working, excluded UDP SWTP-SMS from the VPN community,
> nated the management, allowed UDP SWTP-SMS to the managemnet.
>
>
> >
> > in both cases we see one unencrypted packet UDP SWTP-SMS passing in
> > through the firewall. a packet trace verfies that the packet reaches
> > the management. but no answer at all from the management can be seen
> > in the packet trace.
>
> regards
> ulli

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to