I think then that the best to do is to
(a) Either install a terminal service on his PC or citrix server on a dmz, and let them access the office through that.
(b) Explain him quietly that SecuRemote has no integrated firewall. Secure client has.
(c) Use a cisco router or a win server as a pptp or l2tp 'tunnel end', and do nat.
(d) Don't assume that the security of an inside net can be compromised because of someone not willing to pay for a service.
JF
On Fri, 17 Sep 2004, Mateo Cabrera wrote:
But i only can to controllate ONE firewall...!!!
Imagine that i am the president of a company, and i going to travel, and i located in a hotel with the same subred that my LAN on the company (the target subnet). My remote connection to Internet may be a proxy, a nated router...or a firewall (with the SecuRemote ports open up). My objetive is to cover any posibilities e.g have the same subnet in both locations. What can i do?
Saludos, Mateo Cabrera - Soporte Tecnico Security Advisor www.sadvisor.com
-----Mensaje original----- De: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] nombre de Jean-Francois Gobin Enviado el: viernes, 17 de septiembre de 2004 11:14 Para: [EMAIL PROTECTED] Asunto: Re: [FW-1] Another.....Another..... Another NAT question (SecuRemote)
Everything is possible, even the most obscure things.
You can try this :
Subnet A --> FW A <--- INET ---> FW B <-- Subnet A
Nat Subnet A on FW B behind NET B, so Subnet A on FW A may attack Natted subnet.
On FW A, Nat Subnet A behind NET C.
You should have something like this on your FW :
FW A ----
Subnet A --> NET B * : NET C --> Original Original NET B --> NET C * : Original --> Subnet A Original
FW B ----
Subnet A --> NET C * : NET B --> Original Original NET C --> NET B * : Original --> Subnet A Original
(Or you can "static nat" each host object in its NAT properties).
Another solution is to use a VPN, but in this configuration, you'll have to insure that host in subnet A are not in subnet B.
JF
On Fri, 17 Sep 2004, Mateo Cabrera wrote:
Hi....guys.
The question today is:
Can i to connect from a subnet A to other subnet A (same subnet local and remote) with SecuRemote?, without to use Office Mode.
subnet A----->INTERNET---->FW-1----->subnet A
Saludos, Mateo Cabrera - Soporte Tecnico Security Advisor www.sadvisor.com
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
---------- Jean-Francois Gobin - Administrateur gobinjf.be http://www.gobinjf.be mailto:[EMAIL PROTECTED]
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
---------- Jean-Francois Gobin - Administrateur gobinjf.be http://www.gobinjf.be mailto:[EMAIL PROTECTED]
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
