Lars,

Yes. I can ping/traceroute from any site to the RADIUS servers. the log
shows accept as the implied rule.

Thanks for the help!
Zheng

-----Original Message-----
From: Lars Higham [mailto:[EMAIL PROTECTED]
Sent: Monday, March 01, 2004 10:52 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Help for configuring SecureID ACE server


Hello Zheng,

Have you verified IP connectivit (ping, trace) between the A and B site
firewalls and the RADIUS servers?

Likewise, what's in your logs?  Are your firewalls dropping RADIUS service
packets?

Regards,
Lars Higham



-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Zheng Xu
Sent: Monday, March 01, 2004 11:21 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] Help for configuring SecureID ACE server

Hi,

We have four sites (A,B,C,D) with Nokia 350 and NG-AI R54 and two SecureID
ACE servers. Each site is configured with SecureClient connection. The ACE
server one is located behind site C, the ACE server two is behind site D. We
have only one management server which is behind site A. When a user connects
to site C or D, s/he can be authenticated through ACE servers. When a user
who connects to site A or B, the authentication fails or "RADIUS server at
xxx site is not responding".

We have mesh site-site VPN and remote access defined. Both Accept VPN-1 &
FireWall control connections and Accept Remote Access control connections
are selected. Can you help me?

Thanks in advance,

Zheng
----------------------------------------------------------------------------
---------------------------------------
The information contained in this e-mail is for the exclusive and
confidential use of the addressee.  Any other distribution, use or
reproduction of the information contained in this message, by the addressee
or by any other recipient, is not authorized.  If you have received this
message in error, please notify the sender.

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
-------------------------------------------------------------------------------------------------------------------
The information contained in this e-mail is for the exclusive and confidential use of 
the addressee.  Any other distribution, use or reproduction of the information 
contained in this message, by the addressee or by any other recipient, is not 
authorized.  If you have received this message in error, please notify the sender.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to