> We're trying to set up a vpn between our firewall-1 4.1 and a netscreen
> server.
> The first question I have is about the setup of the local vpn workstation
> object. When it is defined, it is actually a  duplicate of the existing
> gateway
> object (except for the gateway/vpn details). Since it defines the gateway
> itself, the Policy Editor returns a warning that an object already exists.
> Should
> we proceed with the independent object, or  should we just enter the vpn
> config into the existing default firewall object? We tried both.  When we
> created
> a duplicate firewall object, the firewall stopped passing packets. When we
You should not have two objects. The firewall and VPN are the same device.
You should configure the firewalls properties with the necessary VPN
settings.

Too many negotiations can occur because you are not negotiating a key for
the entire subnet and are, instead negotiating a key for every host that
wants to talk to a host across the VPN.

Have you defined an encryption domain on each firewall? In checkpoint this
is under the workstations encryption tab. On the NetScreen this is done
through the "addresses" option and the "policy."

-Don

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to