Ross,

I have removed RADIUS in the implied)rules.def. I t works now.

Thanks all for the help!

Zheng

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]
Sent: Monday, March 01, 2004 11:53 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Help for configuring SecureID ACE server


Hi,


 You may find the problem is due to the fact that the RADIUS auth packets
are being processed by the implied rules and therefore are not traversing
your site to site VPN tunnel. You can edit your implied_rules.def file to
disable this and you should see the RADIUS packets being encrypted as
opposed to being just ACCEPTED. There is a Checkpoint KB article regarding
RADIUS and Implied rules processing.

HTH,


 Ross.

Ross Bushby - Senior Security Architect
Real Solutions Ltd, Unit B&C, Oakcroft Business Centre, Oakcroft
Road,Chessington,Surrey,UK. KT9 1RH.
Tel +44 (0)208 391 4080, Fax: +44 (0)208 391 4081


 N O T I C E
This message and any attachments are intended only for the individual or
company to which it is addressed and may contain information which is
privileged, confidential or prohibited from disclosure or unauthorised use
Any form of dissemination, copying, disclosure, distribution and/or
publication of this e-mail message or its attachments to third parties is
only permitted with the express permission of the sender.
We cannot accept any liability for any loss or damage sustained as a
result of software viruses. It is your responsibility to carry out such
virus checking as is necessary before opening any attachment.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
-------------------------------------------------------------------------------------------------------------------
The information contained in this e-mail is for the exclusive and confidential use of 
the addressee.  Any other distribution, use or reproduction of the information 
contained in this message, by the addressee or by any other recipient, is not 
authorized.  If you have received this message in error, please notify the sender.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to