cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
392
Views
4
Helpful
1
Replies

PIX-CheckPoint Tunnel Troubles

Mark3000
Level 1
Level 1

I am trying to build a VPN tunnel based IPSEC/ISAKMP between PIX and CheckPint NG.

The problem is when enabling all IP the tunnel is OK but when enabling only TCP doesn't work.

Any idea or rec ?

1 Reply 1

michel.mueller
Level 1
Level 1

Checkpoint does not support negotiation of protocol based SA's. To restrict the traffic in the tunnel to TCP use the "no sysopt connection permit-ipsec" command and attach an access-list to the interface which points to the checkpoint firewall. Allow only TCP from the remote IP's in the access-list.

regards Michel

Review Cisco Networking for a $25 gift card