That could be ugly if you can't fix it with a manual NAT rule covering just this VPN.

Ray

From: Kerry Thompson <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1 <[email protected]>
To: [email protected]
Subject: Re: [FW-1] Mako to FW1 VPN IKE problem
Date: Mon, 20 Jun 2005 20:53:41 +1200

Ray said:
> Is it the key retrieval that it's croaking or the CRL retrieval? If the
> latter, check out sk23586
>

I believe its the key retrieval, we're just using pre-shared keys rather
than certificates. The Mako support guys tell us that they're seeing our
FW1 management IP address in the key negotiation and that its illegal, not
being a public IP.

They also tell us they haven't VPN'd a Mako to a Checkpoint firewall
before (although they done others like Cisco), so I suspect there may be a
basic incompatibility.

Kerry

--
Kerry Thompson
http://www.crypt.gen.nz

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to