In my experience you do have to include the firewall objects in the
encryption domain. In my case I have a MEP setup spread across two
continents and this was the only way to create the necessary "full overlap"
of the encryption domains.

Cases where you would not check the exportable for secure remote would be
if you had a site to site VPN (ie. firewall to firewall) and NOT a need for
SecuRemote (ie. client to firewall).


----------------------------------------------------------------------------------------

Greg Winkler
Systems Manager, IT&S
Huntsman Corporation
Internet Mail: [EMAIL PROTECTED]
Voice: (713) 235-6018
Fax: (713) 235-6890




                    Padhu <[EMAIL PROTECTED]>
                    Sent by: Mailing list for discussion        To:     
[EMAIL PROTECTED]
                    of Firewall-1                               cc:
                    <[EMAIL PROTECTED]        Subject:     [FW-1] 
Need for firewall object in the encryption domain ?
                    point.com>


                    03/05/02 10:44 PM
                    Please respond to Mailing list for
                    discussion of Firewall-1





When defining encryption domains it is my understanding that all neworks
behind the firewall need to be included. However i
see that Secure remote doesn't work unless firewall object itself is
included as part of the encryption domain. Any reason why ?

Also, under what conditions would one not select the "Exportable to secure
remote clients" ? SR won't work without this box checked..So i am not sure
what this option really is for.

Thanks.

Cheers,Padhu

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to