Title: SecuRemote and NG FP3
Mayooran,
 
    I do not recall which Sk document I read this in but the IP Pool range needs to be separate from the Internal IP range that is the encryption domain.  So instead of using 192.168.100.100-250 as your pool you may want to try using 192.168.101.1-254 as your range.  If you have any internal routing you will need to put a static route on the internal router or on the servers, unless the firewall is default gateway
 
Chris.
-----Original Message-----
From: Mayooran Pooranachandran [mailto:[EMAIL PROTECTED]]
Sent: Saturday, January 11, 2003 12:27 PM
To: [EMAIL PROTECTED]
Subject: [FW-1] SecuRemote and NG FP3
Importance: High

Hi All,

I have managed to configure CKP NG FP3 (on  Solaris 8 platform) for use with SecuRemote.  All licenses are installed and the configurations were done by the book/docs from SecureKnowledge.  Also configured the firewall to use IP POOL Nat (enabled this options on Global props and defined a range of IP addresses that is part if the internal interface of the firewall i.e.: internal int of firewall is: 192.168.100.2 and the IP pool nat  range is 192.168.100.100-192.168.100.250).

SecuRemote has been configured on Win2K laptop.  Topology download is successful.  All communication (i.e.: telnet/ftp/ping) to the firewall are successful. 

When trying to connect to internal servers, the firewall logs show that the packet is decrypted on hme0 interface but no my traffic nor connection to the internal servers.  Internal servers can ping  hosts on the 192.168.100.0 segment.  There was 1 message that was logged stating: Successfully mapped (SR client's IP address) (192.168.100.101). arp -a from the firewall command line does not show any arp table entries for the mapped IP pool address mentioned above.

Could someone please help me out or point me in the right direction.  All your help will be appreciated (as the current firewall ver 4.0 with 250 user license is causing a lot of problems due to exceeding the number of hosts protected and slowly dies).

Thank you in advance.

---------------------------

Mayooran Pooranachandran

Danier Leather Inc.

Director, Network Services

[EMAIL PROTECTED]

Reply via email to