We have a company which use the Pix as VPN Server. Now we have to connect an internal PC to CheckPoint FW with the SecureRemote Client.
We sniffered the intern and extern site of the Pix with following results:
the client update to the remote site is ok; we see
IKE pakets inside in both directions.
If we try a ping to a remote server , icmp is encapsulated in UDP with dest 2746, the reply reaches the outside of the PIX but not to the inside.
For testing we opened the access-lists but with no success.
Any suggestions ?
Check these documents and see if it helps your situation...
Thanks - Jay
sorry, I preferre the gateway/gateway connection too.
But the customer requires a VPN connection from the inside PC with the SecureRemote Client through the PIX to a CheckPoint FW.
Hi, Just wanted to make sure, is you client behind PAT or static NAT? does the Checkpoint on the other side support NAT-T? what FP is the checkpoint using, you might want to check that.
I would try to give this PC a static NAT translation, and create ACL for it!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: