> *     From: Marc Chauvin <[EMAIL PROTECTED]>
> *     Date: Tue, 19 Feb 2002 02:54:21 +0100
>
> For your information:
>
> After (manually) migrating our Firewall from 4.1 to NG, we
> had a lot of
> VPN problems. SecuRemote users couldn't use MS Exchange
> anymore, and some
> other connections were simply dropped by the NG firewall without any
> warning in the log viewer, nor in vpnd.elg in debug mode.
>
> The solution was to allow NG to fragment IPSec packets. This
> was done by
> using the dbedit command on the management server and editing
> the firewall
> object using the following command:
>
> modify network_objects <name_of_fw_obj> ipsec_dont_fragment false
> update network_objects <name_of_fw_obj>

Marc!

I got exactly the same problems, but when I try to use dbedit:

-------------------- snip --------------------
bash-2.03# dbedit
Enter Server name (ENTER for 'localhost'):

Enter User Name: fwadmin
Enter User Password:

Please enter a command, -h for help or -q to quit:
dbedit> modify network_objects deimos ipsec_dont_fragment false
failed to get field ipsec_dont_fragment
-------------------- snip --------------------

Do you have any idea about this?

Thank you again for your patience!

Stefan Gasteiger
I+K Betrieb (zertifiziert nach DIN EN ISO 9001)
InfraServ Gendorf
Tel.: +49 8679 7 5599
Fax: +49 8679 7 39 5599
Mobiltel.: +49 172 8649205
E-Mail: [EMAIL PROTECTED]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to