I assume you set up a Remote Access rule at the top of your ruleset;
the Smart Tracker logs should tell you if the connection is being
blocked.  If it's not the ruleset, then what OS is running your
enforment module?  Run a packet sniffer (tcpdump, ethereal, snoop)  on
the external and internal interfaces.  Where does the traffic get hung
up?

I run office mode without additional routes on the enforment module
(Solaris 9).  However, I have noticed that the documentation on this
matter is inconsistent, advising that you _may_ need to add routes; in
this case, VPN pool network to firewall IP.

--Greg

On Mon, 2 Aug 2004 19:34:51 +0200, Fabian Tuender <[EMAIL PROTECTED]> wrote:
>
>
> Goodevening,
>
> I hope someone can clear a problem for me. We need to use office mode to
> assign ip address to clients. Without office mode everything works fine, I
> can get a connection with a secureremote client to our firewall and ping any
> address behind it and all trafic passes trough without problems. When I
> enable office mode I get authorised by the firewall but afterwards there is
> no traffic possible trough the tunnel.
> When I setup office mode to use a ip pool outside the subnet of our internal
> side of the firewall the connection fails. In the log I only see that I am
> authenticated successfull and I get a ip address assigned but then it ends.
> When I setup office mode to use a ip pool inside the subnet of our internal
> side of the firewall I get a connection but there is no traffic possible
> trough that tunnel. I have a new network adapter with a ip address from the
> pool but nothing happens. On the firewall I see no traffic but only
> sometimes a broadcast from that client on the subnet. On the clients log
> viewer I get the message: encryption fail reason::Packet if from physical ip
> address but office mode is active.
>
> I have read the office mode documents on and on but cannot find why its not
> working. Anyone with an idea is welcome, thanx in advance.
>
> With kind regards,
>   Fabian
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to