hi,

At 09:46 15.07.2004, you wrote:
Hi,

I made a VPN Connection with SecureClient behind a NAT device.
The Client uses UDP Encapsulation and all is working.

Why cant i see the UDP packets in the log?

what log do you mean? firewall or NAT-device? you should be able to see the logs on both points.

If i sniff on the external interface and ping from remote client to an
internal client the packets from remote are encapsulated and the reverse
packets clear. Whats up?

09:38:41.160346 checkpoint.1297 > natrouter.2746:  udp 92
09:38:42.160568 192.168.0.40 > 192.168.1.10: icmp: echo request
09:38:41.160346 checkpoint.1297 > natrouter.2746:  udp 92
09:38:42.160568 192.168.0.40 > 192.168.1.10: icmp: echo request

maybe icmp is allowed without encryption? check your rulebase ...

cheers
reinhard

Thx for help
jo

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

-- Reinhard Stich ASSIST [EMAIL PROTECTED] Internet Security AG, 1150 Wien, Johnstrasse 29 Tel: +43 1 3709440 RS784-RIPE Fax: +43 1 3709440-333

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to