This article might help: skI2208 - How to configure a Gateway-to-Gateway VPN with a non-routable IP address as the main IP address?
If you're seeing log entries referencing this: What to do when getting error message, "VPN out of state connection type" while doing VPN with Cisco PIX", check out article sk15949 - I've seen this one mentioned often when the VPN seems to be one-way.
Ray
From: Jim Burwell <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [FW-1] NG FW-1 object w/ private IP...will VPN function ? Date: Sat, 10 Apr 2004 00:55:02 -0700
Hi...
I'm trying to establish an IPSEC VPN between a Cisco router (12.2) and a customer's CPNG w/AI (R55) Firewall.
Unfortunately, the FW was configured so that the FW object's IP is the inside private IP address. I'm not super familiar w/ NG, but I know under 4.1 that was a real no-no, and VPNs wouldn't not work if the FW object's IP wasn't the FW's public IP. Is this also true for NG, or did they build a bit more intelligence into CPNG to deal with this situation ?
It appears that the IKE/IPSEC stuff is establishing OK, and the log shows the FW decrypting packets from the Cisco side of the VPN to the FW1 side, but I don't get any reply packets, or log entries indicating return traffic. The FW log entries also show that these IPSEC packets sourced from the Cisco have a destination of the FW's private/inside address (suprisingly being tunneled via ESP across the internet to arrive at the FW). This makes me suspect that the whole problem is the good 'ole "FW object IP" issue.
Presuming that the FW object's IP must be changed to the external to make the VPN work, will changing this object break SIC, or anything else ? Or can one simple change the FW object's IP to it's public address w/o fear of breaking things ?
Thanks, Jim
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
_________________________________________________________________ Persistent heartburn? Check out Digestive Health & Wellness for information and advice. http://gerd.msn.com/default.asp
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
