Dear All,

I had a VPN question, the following is my requirement & scenario:

Scenario is: (Raidus Server behind FW1)
"Radius Server"  --> FW1 --> Internet <-- FW2

Requirement: Have a "client authention w/ radius authentication" rule at
FW2, and I want to encrypt "radius" service between FW2 & Radius Server

My Setting:
At "FW1" encryption domain, which include "radius server"
At "Fw2" encryption domain, which include "FW2"

My testing:
- "ftp" from radius server to FW2 (VPN success)
- "ftp" from FW2 to radius server (VPN success)
- "client authention" from radius server to FW2 (VPN success), but
authentication fail due to cannot contact radius server.  The following is a
error found in firewall logs:

<< encryption fail reason: Different community ID, possible NAT problem >>

Question:
Anybody know that how to setup firewall policy for my requirement?


Remarks: If I exclude "radius" from encryption, the authentication is OK.
And My firewall haven't any NAT rules because my all IP address is valid.

Thanks
Kingsley

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to