Ross, I have removed RADIUS in the implied)rules.def. I t works now.
Thanks all for the help! Zheng -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Monday, March 01, 2004 11:53 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] Help for configuring SecureID ACE server Hi, You may find the problem is due to the fact that the RADIUS auth packets are being processed by the implied rules and therefore are not traversing your site to site VPN tunnel. You can edit your implied_rules.def file to disable this and you should see the RADIUS packets being encrypted as opposed to being just ACCEPTED. There is a Checkpoint KB article regarding RADIUS and Implied rules processing. HTH, Ross. Ross Bushby - Senior Security Architect Real Solutions Ltd, Unit B&C, Oakcroft Business Centre, Oakcroft Road,Chessington,Surrey,UK. KT9 1RH. Tel +44 (0)208 391 4080, Fax: +44 (0)208 391 4081 N O T I C E This message and any attachments are intended only for the individual or company to which it is addressed and may contain information which is privileged, confidential or prohibited from disclosure or unauthorised use Any form of dissemination, copying, disclosure, distribution and/or publication of this e-mail message or its attachments to third parties is only permitted with the express permission of the sender. We cannot accept any liability for any loss or damage sustained as a result of software viruses. It is your responsibility to carry out such virus checking as is necessary before opening any attachment. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ------------------------------------------------------------------------------------------------------------------- The information contained in this e-mail is for the exclusive and confidential use of the addressee. Any other distribution, use or reproduction of the information contained in this message, by the addressee or by any other recipient, is not authorized. If you have received this message in error, please notify the sender. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
