Does anyone have experience of SecuRemote R56 working fine behind a IOS router with CBAC running?
We have strange situation where I can see all necessary traffic for securemote client on the firewall:
UDP/500
UDP/2746
UDP/259
When it starts acting up I see many UDP/259 NAT sessions to various servers in the cluster. When checkpoint administrator says it look like the SA cant be renegoiated.
I tried changing UDP timeout and NAT. I went as far as adding another CBAC inbound (outside) and an any rule from the FW-1 server?
This apparently works fine when the cisco box is removed form the equation. IOS is ver 12.4 running adv IP services.
I'm at a total loss with this, sometime it works then just stops working - maybe when the SA can negotiate?