OK, well, let's start with the basics:

Are you using the implied rules for control connections and for remote
access?

Are you logging implied rules?

Was this a clean R55 install or did you do an upgrade from 4.1 in the test
environment?

In the firewall, do you have the "exportable for SecuRemote" box checked?
Sorry, but I can't remember exactly where it is. Under some "advanced"
button or maybe under a "traditional mode" button. Yes, you have to do it
even if you are using simplified rules and the button s found under
"traditional".

Ray

From: Robert Filipovich <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[email protected]>
To: [email protected]
Subject: Re: [FW-1] Securemote Problems
Date: Wed, 23 Feb 2005 17:00:31 -0500

Well it is 69.38.66.1 but the new firewall is in a lab environment.

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Stala
Sent: Wednesday, February 23, 2005 4:22 PM
To: [email protected]
Subject: Re: [FW-1] Securemote Problems

so was it the IP of the firewall object?
----- Original Message -----
From: "Robert Filipovich" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Tuesday, February 22, 2005 9:58 PM
Subject: Re: [FW-1] Securemote Problems


Using FW monitor the only traffic I see is FW_top request from the client and nothing from the firewall. I guess I mispoke with not connecting to the external interface. I can see the request but the firewall does nothing with the request according to the logs. I am from a 4.1 setup and this is my first NG setup and everything else works fine.

Any ideas would be great.  I have pulled every technote I can find.

/Robert

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Ray
Sent: Tuesday, February 22, 2005 8:55 PM
To: [email protected]
Subject: Re: [FW-1] Securemote Problems

How can you not have a connection to the external interface if that is
the IP address of the site? Are you sure you have a route?

You don't have the firewall object set to the internal interface IP oif
the gateway, do you?

Ray

>From: Robert Filipovich <[EMAIL PROTECTED]>
>Reply-To: Mailing list for discussion of Firewall-1
><[email protected]>
>To: [email protected]
>Subject: Re: [FW-1] Securemote Problems
>Date: Tue, 22 Feb 2005 16:40:59 -0500
>
>Yes and the one above that NG with Application Intelligence R55 HFA-03
>and NG with Application Intelligence R56 HFA-02 (Build 615).
>
>/Robert
>
>-----Original Message-----
>From: Mailing list for discussion of Firewall-1
>[mailto:[EMAIL PROTECTED] On Behalf Of
>Previtera, Sal
>Sent: Tuesday, February 22, 2005 2:10 PM
>To: [email protected]
>Subject: Re: [FW-1] Securemote Problems
>
>Robert,
>You have not mentioned what version of Securemote you are using?
>Have you tried with Securemote version comparable to R55?
>
>-----Original Message-----
>From: Mailing list for discussion of Firewall-1
>[mailto:[EMAIL PROTECTED] On Behalf Of Robert

>Filipovich
>Sent: Tuesday, February 22, 2005 11:49 AM
>To: [email protected]
>Subject: [FW-1] Securemote Problems
>
>Good Day,
>
>We are attempting to upgrade to a NG AI R55 and we are currently using
>4.1sp5.  I am following every technote I can find to setup remote users

>and nothing is working.  I am using a lab setup to test and never get a

>connection to the outside interface and never even see a transaction
>logged.  I can see a TCPdump hitting the interface but nothing else is
>working.  Am I missing something or is there something weird to look
>for on the securemote setup.  Everything else has transitioned well,
>but I can't roll this out until it works.
>
>Thanks,
>/Robert Filipovich
>
>=================================================
>To set vacation, Out-Of-Office, or away messages, send an email to
>[EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your subscription options,
>email [EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out-Of-Office, or away messages, send an email to
>[EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your subscription options,
>email [EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out-Of-Office, or away messages, send an email to
>[EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your subscription options,
>email [EMAIL PROTECTED]
>=================================================

=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options,
email [EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================

Reply via email to