Why does the client at HQ need to connect to the external interface of the
remote firewall?
In a simplified security policy, all enforcement modules are automatically
part of th encryption domain.
Ray
From: FITZ MAILING <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[email protected]>
To: [email protected]
Subject: [FW-1] External Interface automatic in Encryption Domain???
Date: Wed, 2 Nov 2005 16:55:06 +0100
Hi guys,
I have following scenario:
A headquarter with a Management Server and a Firewall
Modul to the Internet. A remote office with another
Firewall Modul, that is managed by the Management
Server at the headquarter.
The VPN-Domains are manual defined and includes only
the internal networks at both sides. I use
VPN-Communites and the traffic between the internal
networks is encrypted.
I have a Client, that is part of the Encryption Domain
at the headquarter and I want, that this client can
connect to the external Interface (Internet) of the
Firewall Modul at the remote office without using the
VPN tunnel. Therefore I do NAT at the Firewall Modul
at the headquarter.
Because the external Interface of the Firewall Modul
at the remote location is not part of the manual
defined VPN-Domain this should work. But unfortunately
the Firewall Module at the headquarter routes this
traffic through the tunnel. It seems that all
interface of the modul are automaic part of the
encrpytion domain...
The only solution is to exclude this client from the
manual encryption domain of the headquarter, but this
is no solution.
Has anyone a solution for me, it drives me crazy ;-)
best regards fitz
___________________________________________________________
Gesendet von Yahoo! Mail - Jetzt mit 1GB Speicher kostenlos - Hier
anmelden: http://mail.yahoo.de
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================