NG AI R55 HFA_503

Hi All,

I'm new to Checkpoint VPNs and have a problem with encryption domains cause
by dodgy design choices which I'm hoping there is a way around.

I have 2 web servers behind a Nokia cluster running NG AI R55 HFA_503 with
VPN in simplified mode. All traffic to these web servers comes from 3 remote
proxy servers behind a third-party Checkpoint 4.1 VPN-1/FW-1. Traffic to the
first webserver needs to arrive in the clear over the internet. Traffic to
the second comes down a VPN...

With both webservers in my encryption domain I logged:
"encryption failure: Received a cleartext packet within an encrypted
connection"
When attempting to connect to webserver2 via the proxy server.
I made it work by just excluding webserver 2 from my firewall's encryption
domain. However, I would like to get webserver 2 back into the encryption
domain so that it can be reached by another vpn from one of our sites.

Short of encrypting everything does anyone have any ideas on how to solve
this stupid problem?

Thanks,

Phil Hayward

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to