Hi,
I am having a few problem getting SSL authentication working for an external
client through to an internal web server (SSL between client and gateway
only)  Version NG +FP1, firewall and management on the same host. I have
followed the instructions in the firewall-1 guide but I am unable to make it
work. There is nothing in the log at all, however, the active log shows the
session as being accepted.  The browser simply times out.
Modifying the service to HTTP and performing unencrypted authentication
works correctly.

Is there any specific syntax for the certifcate name for the fwauthd.conf
file when defining the security server - is the name needed at all? ie

443     fwssd   in.ahttpd       wait    0       ec: certificate name

Does this configuration require a separate SSL certificate?

Any other pointers as to what might be going wrong would be most
appreciated.

Regards







==========================================================================
This message and any attachments are confidential and may also be
privileged.
Its contents do not constitute a commitment by the Channel Tunnel Group Ltda
 nd/or France-Manche S.A. except where provided for in a written agreement
between you and The Channel Tunnel Group Ltd and/or France-Manche S.A.
Any unauthorised disclosure, use or dissemination, either whole or partial
is prohibited. If you are not the intended recipient of the message, please
notify the sender immediately. The views expressed in this message do not
necessarily reflect those of The Channel Tunnel Group Ltd and/or
France-Manche
S.A. or any of their subsidiary companies.

Ce message et ses annexes sont confidentiels et peuvent contenir des
informations prot�g�es par le secret professionnel. Son contenu ne
repr�sente
en aucun cas un engagement de la part de The Channel Tunnel Group Ltd
et/ou France-Manche S.A. sous r�serve d'un accord conclu par �crit entre
vous et
The Channel Tunnel Group Ltd et/ou France-Manche S.A. Toute publication,
utilisation ou diffusion, m�me partielle, est interdite. Si vous n'�tes pas
destinataire de ce message, merci d'en avertir imm�diatement l'exp�diteur.
Les opinions exprim�es dans ce message ne refl�tent pas n�cessairement
celles de The Channel Tunnel Group Ltd et/ou France-Manche S.A.
ou de leurs soci�t�s filiales

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to