It's not possible for failover for you to partially overlap the domains. If
you can somehow make both 10.0.0.0, or somehow make them fully overlap, then
MEP is possible.

Thomas Poole

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, August 23, 2000 2:23 AM
To: [EMAIL PROTECTED]
Subject: [FW1] partial overlapped encryption domains



Hi,

We have a situation like:
***Migrating thousands of SecureRemote users from one Vpn-1x 4.1.SP1 to
another H.A. Vpn-1y 4.1. SP1.
* There's an existing encryption domain on Vpn-1x and existing encryption
domain on Vpn-1y.
* I can not force for all the users to make site update, and it's not very
easy because SecureRemote is bundled in another application and not visible
on the desktop.
* Management Server is the same for the 2 Vpn-1.
* Moreover, I am planning to make the system accessible from the two
firewalled gateways. In short, users do not need to make site update. Is it
possible?

When I am trying to configure the encryption domains on the Vpn-1s with the
same subnet included, than the SecureRemote Clients can not make site
update hence there's an error of "partially overlapped encyrption domains".
What do you suggest to overcome this situation?

Regards.

Ihsan Cakmakli
Bilpa A.S.



============================================================================
====
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
============================================================================
====


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to