-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,


My test environment is NG FP3 on Linux 7.3 and SecuRemote 53328 on W2k
behind OpenBSD 3.2 PF/NAT

I'm trying to create site.
It does not work so far. :(

I sniffed the traffic between FW and NAT device.

Here is interesting part

16:19:39.550591 fi.re.wa.ll.isakmp > o.bsd.pf.nat.59225: isakmp 1.0
msgid 00000000: phase 1 R ident[E]: [|id] (len mi
smatch: isakmp 1628/ip 1472) (frag 64242:1480@0+) (ttl 64, len 1500)
~                         4500 05dc faf2 6000 4011 ea01 xxxx xxxx
~                         xxxx xxxx 01f4 e759 0664 8b4a dbeb 48d5


The packets has both DF and MF set.
OBSD PF scrub in all, srcub out all is going to discard those packets.

Is this Linux bug?
CP?
OBSD?
Any comments?

Does anybody get such configuration working?


- --
Thanks,

Vadim Kuznetsov
Systems Administrator

Sapiens Americas

http://www.sapiens.com/
"Modernizing Business Processes Through Proven IT Solution"

Phone: 919-405-1563 Toll free: 800-858-9473x563 Fax: 919-405-1700


2000 CentreGreen Way, Suite 240
Cary, NC 27513

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)

iD8DBQE+Ns3cZlJj7TmMsZ8RAgpZAJ9pMNuLsX1i7cTOmzCQfwLEjpn4/ACgpF+C
/P+n73xu85f4hmZk/rAnbM0=
=tIM8
-----END PGP SIGNATURE-----

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to