09-16-2003 02:14 AM - edited 02-20-2020 10:59 PM
We have a company which use the Pix as VPN Server. Now we have to connect an internal PC to CheckPoint FW with the SecureRemote Client.
We sniffered the intern and extern site of the Pix with following results:
the client update to the remote site is ok; we see
IKE pakets inside in both directions.
If we try a ping to a remote server , icmp is encapsulated in UDP with dest 2746, the reply reaches the outside of the PIX but not to the inside.
For testing we opened the access-lists but with no success.
Any suggestions ?
Wolfgang
09-16-2003 06:20 AM
Hi Wolfgang,
Check these documents and see if it helps your situation...
http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00800ef796.shtml
Thanks - Jay
09-16-2003 06:42 AM
sorry, I preferre the gateway/gateway connection too.
But the customer requires a VPN connection from the inside PC with the SecureRemote Client through the PIX to a CheckPoint FW.
Thanks
Wolfgang
09-16-2003 02:04 PM
Hi, Just wanted to make sure, is you client behind PAT or static NAT? does the Checkpoint on the other side support NAT-T? what FP is the checkpoint using, you might want to check that.
I would try to give this PC a static NAT translation, and create ACL for it!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide