Check Point IPSEC traffic? If so, you're probably seeing drops on Rule 0 because of the "accept remote access traffic" implied rule. You would need to remove that implied rule, make sure your site-to-site rule allows remote access traffic and then create a new rule after the site-to-site rule to accept the remore access traffic.
If I'm thinking correctly this morning, that is. :-)
Ray
From: Steve Loughran <[EMAIL PROTECTED]> Reply-To: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [FW-1] LAN-2-LAN IPSEC inside IPSEC VPN? Date: Thu, 30 Sep 2004 08:06:35 +0100
Hi all
On NG R55, is it possible to have LAN to LAN IPSEC traffic go via site to site IPSEC VPN? I am having a few problems with it this morning, the firewalls at either end are dropping it because they think its firewall to firewall IPSEC, dont understand it, and drop it.
Any clues or tips? Or will this always fail?
Steve
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
_________________________________________________________________ Don�t just search. Find. Check out the new MSN Search! http://search.msn.click-url.com/go/onm00200636ave/direct/01/
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
