Hi,
I have the following Problem and want to ask if this is possible:
I have two Sites (A and B), both have their own Gateways and both have a
SmartCenter, and they 're connected via Site To Site VPN.
The SmartCenter of B is broken, so I'm not able to install a Policy at
B's Gateways, nevertheless the communication is still fine.
For debugging Reasons, I'd like to Access B's SmartCenter from a third
Site C, wich is difficult, because as said, I can't install a Policy at
B's site.
BUT there's a Host in Site A (10.10.0.2) that is allowed to talk to B's
SmartCenter.
I tried to use the Adress of this Host and the existing VPN between A
and B to grant access to C in the following Way (remember, I'm only
working with A's policy)
I Created a 'SmartCenterB' Object with it's LAN Adress (10.20.0.20) and
static NATed it behind a Public Adress of SiteA (193.1.1.2)
Then I created a 'HostC' object with it's public IP (194.1.1.2).
Now I've a Security Rule "From 'HostC' to 'SmartCenterB' allow all"
In Addition I've created a NAT Rule: SRC:HostC, DST:SmartCenterB,
XlateSRC:HostA, XlateDST:original, where 'HostA' is the address of an
Host in Site A that is allowed to Access 'SmartCenterB' (in both, A's
and B's Security Policy)
Should this work out? Because as you may guess, it's not.
traceroute 'SmartCenterB' issued on 'HostC' shows me the Connection
until SiteA Gateway. In SiteA SmartTracker I can see the Connection, it
looks ok, but it's not forwarded via VPN :(
Any Ideas if this one is possible, and how I can resolve this?
kind regards, Markus
--
Markus Schmidt Tel.: ++49-351-3 18 09 27
interface systems GmbH Fax.: ++49-351-3 36 11 87
Tolkewitzer Straße 49 E-Mail: [EMAIL PROTECTED]
D-01277 Dresden
Ein Unternehmen der interface:business-Gruppe
Scanned by Check Point Total Security Gateway.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================