> Within the Topology tab of the Firewall object set the VPN
> domain to be
> specific (or other - can't remember exact terminology off the
> top of my
> head), and include only the internal network object (or group that
> contains the networks you need access to).


I added only 10.49.4.x into the VPN domain.

SR--192.168.1.x---NAT---Internet----Checkpoint---10.0.49.x
                                        |
                                   192.168.1.x

The result in usersc.c is
:gws (
                : (xxxxx.xxxx
                        :obj (
                                : (x.x.x.x)
                        )
                        :keymanager (
                                :type (refobj)
                                :refname ("#_itsec")
                        )
                        :allowed_interface_ranges (
                                : (192.168.1.1
                                        :allowed_range (
                                                : (
                                                        :type
(machines_range)
                                                        :ipaddr_first
(192.168.1.0)
                                                        :ipaddr_last
(192.168.1.255)

There is no entry in the topology key
After connecting with vpn, the client cant connect to everthing in the local
network
If comment out the 192.168.1.0 from the allowed areas all is working.

Thx for help
jo

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to