Hi Jo�o, we needed to terminate a VPN on an internal interface because there were using a dedicated leased line between the two sites. We needed to do the following changes to get it to work.
======================================================================== "Please do a 'cpstop' on the FireWall Management server, then edit the objects_5_0.C file and change the following setting for the FireWall Object that is doing the VPN, from 'false' to 'true'. Make sure you are making the change on the FireWall that is doing the site to site VPN. Do a search for this variable 'resolve_multiple_interface' and change it to 'true'. Do a search for this variable 'resolve_multiple_interface_GW' and change it to 'true'. Save the changes. Do a 'cpstart', and then install the policy again on the VPN module." ======================================================================== I think this might solve you problem. Best regards, Mark William Lane Dipl.-Inform.(FH) Installation & Implementation Manager CCSA/CCSE-2000, CCSA/CCSE-NG Certified Sonicwall Global Manager SNC Secure Networking Company AG Making the Internet Secure for You! [EMAIL PROTECTED] Tel.: +49 (0)6131-97147-0 Fax: +49 (0)6131-97147-99 www.sncag.com PGP Fingerprint: 9B45 52D7 FCBD B0AA 21E0 1223 DEBF 25E8 3321 4EB1 -------------- Diese Nachricht kann vertrauliche Informationen enthalten. Wenn Sie nicht der in der Nachricht enthaltene Empf�nger sind (oder verantwortlich f�r die �berbringung der Nachricht zu dieser Person), sind sie nicht befugt, diese zu kopieren oder einer beliebigen Person zu �berbringen. In diesem Fall l�schen Sie bitte diese Nachricht und informieren Sie den Absender mit Hilfe einer R�ckantwort per Email. Bitte unterrichten Sie uns unverz�glich, wenn Sie oder ihr Arbeitgeber einer �bermittlung von Nachrichten dieser Art mittels Internet nicht zustimmen. �berzeugungen, R�ckschl�sse und andere Informationen, die in dieser Nachricht enthalten sind und nicht zu den offiziellen Gesch�ftsgepflogenheiten unserer Firma geh�ren, werden nicht unterst�tzt und als nie erkl�rt gewertet. -------------- Confidential Information may be contained in this message. If you are not the addressee indicated in this message (or responsible for delivery of the message to such person), you may not copy or deliver this message to anyone. In such case, you should destroy this message and kindly notify the sender by reply email. Please advise immediately if you or your employer does not consent to Internet email for messages of this kind. Opinions, conclusions and other information in this message that do not relate to the official business of my firm shall be understood as neither given nor endorsed by it. -------------- -----Urspr�ngliche Nachricht----- Von: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] Im Auftrag von Jo�o Serras Rodrigues Gesendet: Freitag, 13. Februar 2004 18:05 An: [EMAIL PROTECTED] Betreff: [FW-1] Terminating a VPN in a secondary interface Hi, I have a Gateway cluster (using StoneBeat FullCluster) NG R54 with several interfaces. Two of them are connected to the outside world (Internet) using the IP of (only!) one of them in the General Properties of the gateway cluster object. I'm trying to terminate a VPN in the other interface. The IKE negotiation it's ok and the SAs are established but when the ESP traffic begins the IP that is appearing in the other VPN peer in the one that is defined in the gateway cluster general properties and I don't want that. I want the other peer only to see the IP address of that interface since that's where the traffic comes and goes. I have defined both interfaces as external. I have static routing line forcing the traffic of that VPN (other peers IP and encryption domain) to go through that interface but still the ESP packet reaches the other end with a different IP address. Any ideas!? Thanks, Jo�o Rodrigues ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
