No, my site-to-site VPN's are holding (at least so far)!  Only my
SecureClient users are having problems.
Sure with Check Point had warned me about this in the HFA08 release notes.

I am trying to get the hotfix SHF_FW1_R55_0123 that was recommended, but
Check Point is dragging their feet
and informed me that HFA_09 will be released ASAP (whatever that means).

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Mark
Southgate
Sent: Friday, August 13, 2004 3:44 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Beware R55 HFA08!


Joe

Did you have any issues with Site to Site VPN.  I applied HFA08 to a VIG
this week and I ended up with VPN Error code 02 caused by the Firewall
attempting to terminate the VPN on an address from a secondary range rather
than the primary.  I can't be sure that this was not an issue with the
set-up on the Firewall and the topology as when the topology was updated it
would only display the secondary range on the External Interface.

Mark


-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of Joe Pope
Sent: 12 August 2004 16:48
To: [EMAIL PROTECTED]
Subject: [FW-1] Beware R55 HFA08!


Warning if use VPN with R55, especially SecuRemote/SecureClient!

After upgrading from HFA04 to HFA08 we started having decryption errors (VPN
error code 03) with our SecureClient users. Somehow the logged IP address of
the VPN Peer Gateway is getting changed (by the firewall) and then
decryption fails.  It does not affect all SecureClient users at the same
time, and after a few hours the problem goes away!  I checked my
SecureClient while monitoring my firewall logs, and my SecureClient IP
address was not being reported in the firewall logs correctly.

I submitted a trouble ticket with Check Point and they know about this
problem, and they suggested I  roll back to HFA04. They said HFA09 is
suppose to fix this problem, but no word on when to expect this fix.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


This e-mail is confidential and may well also be legally privileged. If you
have received it in error, you are on notice of its status.  Please notify
us immediately by reply e-mail and then delete this message from your
system.  Please do not copy it or use it for any purposes, or disclose its
contents to any other person:  to do so could be a breach of confidence.
Thank you for your co-operation.  Please contact our IT Helpdesk on +44 (0)
20 7936 4000 Ext.2000 or email [EMAIL PROTECTED] if you need
assistance.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to