I assume you set up a Remote Access rule at the top of your ruleset; the Smart Tracker logs should tell you if the connection is being blocked. If it's not the ruleset, then what OS is running your enforment module? Run a packet sniffer (tcpdump, ethereal, snoop) on the external and internal interfaces. Where does the traffic get hung up?
I run office mode without additional routes on the enforment module (Solaris 9). However, I have noticed that the documentation on this matter is inconsistent, advising that you _may_ need to add routes; in this case, VPN pool network to firewall IP. --Greg On Mon, 2 Aug 2004 19:34:51 +0200, Fabian Tuender <[EMAIL PROTECTED]> wrote: > > > Goodevening, > > I hope someone can clear a problem for me. We need to use office mode to > assign ip address to clients. Without office mode everything works fine, I > can get a connection with a secureremote client to our firewall and ping any > address behind it and all trafic passes trough without problems. When I > enable office mode I get authorised by the firewall but afterwards there is > no traffic possible trough the tunnel. > When I setup office mode to use a ip pool outside the subnet of our internal > side of the firewall the connection fails. In the log I only see that I am > authenticated successfull and I get a ip address assigned but then it ends. > When I setup office mode to use a ip pool inside the subnet of our internal > side of the firewall I get a connection but there is no traffic possible > trough that tunnel. I have a new network adapter with a ip address from the > pool but nothing happens. On the firewall I see no traffic but only > sometimes a broadcast from that client on the subnet. On the clients log > viewer I get the message: encryption fail reason::Packet if from physical ip > address but office mode is active. > > I have read the office mode documents on and on but cannot find why its not > working. Anyone with an idea is welcome, thanx in advance. > > With kind regards, > Fabian > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
