Hi Jo�o,

we needed to terminate a VPN on an internal interface because there were
using a dedicated leased line between the two sites.
We needed to do the following changes to get it to work.

========================================================================
"Please do a 'cpstop' on the FireWall Management server, then edit the
objects_5_0.C file and change the following setting for the FireWall
Object
that is doing the VPN, from 'false' to 'true'.

Make sure you are making the change on the FireWall that is doing the
site to site VPN. Do a search for this variable
'resolve_multiple_interface' and change it
to
'true'.
Do a search for this variable 'resolve_multiple_interface_GW' and change

it
to 'true'.
Save the changes.
Do a 'cpstart', and then install the policy again on the VPN module."
========================================================================

I think this might solve you problem.

Best regards,

Mark William Lane
Dipl.-Inform.(FH)
Installation & Implementation Manager
CCSA/CCSE-2000, CCSA/CCSE-NG
Certified Sonicwall Global Manager

SNC Secure Networking Company AG
Making the Internet Secure for You!

[EMAIL PROTECTED]
Tel.: +49 (0)6131-97147-0
Fax: +49 (0)6131-97147-99
www.sncag.com

PGP Fingerprint:
9B45 52D7 FCBD B0AA 21E0 1223 DEBF 25E8 3321 4EB1

--------------
Diese Nachricht kann vertrauliche Informationen enthalten. Wenn Sie
nicht der in der Nachricht enthaltene Empf�nger sind (oder
verantwortlich f�r die �berbringung der Nachricht zu dieser Person),
sind sie nicht befugt, diese zu kopieren oder einer beliebigen Person zu
�berbringen.
In diesem Fall l�schen Sie bitte diese Nachricht und informieren Sie den
Absender mit Hilfe einer R�ckantwort per Email. Bitte unterrichten Sie
uns unverz�glich, wenn Sie oder ihr Arbeitgeber einer �bermittlung von
Nachrichten dieser Art mittels Internet nicht zustimmen. �berzeugungen,
R�ckschl�sse und andere Informationen, die in dieser Nachricht enthalten
sind und nicht zu den offiziellen Gesch�ftsgepflogenheiten unserer Firma
geh�ren, werden nicht
unterst�tzt und als nie erkl�rt gewertet.
--------------
Confidential Information may be contained in this message.  If you are
not the addressee indicated in this message (or responsible for delivery
of the message to such person), you may not copy or deliver this message
to anyone.
In such case, you should destroy this message and kindly notify the
sender by reply email. Please advise immediately if you or your employer
does not consent to Internet email for messages of this kind.  Opinions,
conclusions and other information in this message that do not relate to
the official business of my firm shall be understood as neither given
nor endorsed by it.
--------------
-----Urspr�ngliche Nachricht-----
Von: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Im Auftrag von Jo�o
Serras Rodrigues
Gesendet: Freitag, 13. Februar 2004 18:05
An: [EMAIL PROTECTED]
Betreff: [FW-1] Terminating a VPN in a secondary interface

Hi,

I have a Gateway cluster (using StoneBeat FullCluster) NG R54 with
several interfaces.
Two of them are connected to the outside world (Internet) using the IP
of (only!) one of them in the General Properties of the gateway cluster
object.
I'm trying to terminate a VPN in the other interface. The IKE
negotiation it's ok and the SAs are established but when the ESP traffic
begins the IP that is appearing in the other VPN peer in the one that is
defined in the gateway cluster general properties and I don't want that.
I want the other peer only to see the IP address of that interface since
that's where the traffic comes and goes.
I have defined both interfaces as external.
I have static routing line forcing the traffic of that VPN (other peers
IP and encryption domain) to go through that interface but still the ESP
packet reaches the other end with a different IP address.

Any ideas!?

Thanks,

Jo�o Rodrigues

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to