Dear All, I had a VPN question, the following is my requirement & scenario:
Scenario is: (Raidus Server behind FW1) "Radius Server" --> FW1 --> Internet <-- FW2 Requirement: Have a "client authention w/ radius authentication" rule at FW2, and I want to encrypt "radius" service between FW2 & Radius Server My Setting: At "FW1" encryption domain, which include "radius server" At "Fw2" encryption domain, which include "FW2" My testing: - "ftp" from radius server to FW2 (VPN success) - "ftp" from FW2 to radius server (VPN success) - "client authention" from radius server to FW2 (VPN success), but authentication fail due to cannot contact radius server. The following is a error found in firewall logs: << encryption fail reason: Different community ID, possible NAT problem >> Question: Anybody know that how to setup firewall policy for my requirement? Remarks: If I exclude "radius" from encryption, the authentication is OK. And My firewall haven't any NAT rules because my all IP address is valid. Thanks Kingsley ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
