You also need to allow UDP port 500 through. UDP 500 = IKE

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of
[EMAIL PROTECTED]
Sent: Thursday, June 03, 2004 8:49 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] SecuClient and Pix Firewall

Mitesh,

Couple things here.  For the ports to open on the PIX, check the
Checkpoint knowledgebase for article sk14617.  Also another gotcha that
can sometime occur; if your running an ACL on your outside internet
router don't forget to allow that same traffic out (like the ESP or AH
stuff).

But for the Checkpoint client behind the MS ISA server, my understanding
is this doesn't work well because the ISA server malforms the packet to
much so as to cause the VPN gateway to drop the packets.  Some blame MS
for a bad product, MS blames lack of NAPT (though every other vendor
seems to have figured this out)
(http://www.isaserver.org/articles/IPSec_Passthrough.html).  But I'll
bet someone here has figured this issue out.

Good luck!

Kevin




                               Mitesh Shetty/MUM/IN/STTL
                               <[EMAIL PROTECTED]>  To:
[EMAIL PROTECTED]
                               Sent by: Mailing list for cc:
                               discussion of Firewall-1  Subject:
[FW-1] SecuClient and Pix Firewall
                               <[EMAIL PROTECTED]
                               .US.CHECKPOINT.COM>


                               06/03/2004 05:56 AM
                               Please respond to Mailing
                               list for discussion of
                               Firewall-1





Hello,
We want to install SecuClient(NG-FP3) on a client machine(win2k) which
is behind a ISA proxy server and pix firewall .
Would my Vpn client work behind a ISA proxy server?
We wanted to know what are the ports that need to opened on the Pix
firewall and ISA proxy server for the vpn client to communicate with our
Checkpoint NG-R54 firewall .
Thanks in advance .

Regards
Mitesh S Shetty
Technical Support (Security)
Softcell Technologies Limited.

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options,
email [EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options,
email [EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to