Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


[FW-1] Secure remote Problem
.

  • To: [EMAIL PROTECTED]
  • Subject: [FW-1] Secure remote Problem
  • From: robert lewis <[EMAIL PROTECTED]>
  • Date: Wed, 23 Mar 2005 17:56:34 +0530
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:mime-version:content-type:content-transfer-encoding; b=AVgt4CckqJE/EVmAcGaGPrhQyiS0ZO5cxmeV74rwloo0f4nqY+QDnUUpZY/GnbFKbJstEje0n2JxKx3OUpoD3OGVkxGPPoPx1UocPvqUpPOwz/QhC0NK+uococYysO+poOd0wUqsATHmBQL/gZ+qHnKSzj82IpJW0TuZXH/7LWI=
  • Reply-to: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]>
  • Sender: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]>
.
 
We have a checkpoint firewall R55 ,and have configured remote access
vpn(which was working perfect until now)we have a peculiar problem
,whenever any securemote user tried to create a site he is thrown the
authentication challenge and after IKE just hangs ending in "failed to
communciate with gateway x at site x"
When i check the firewall logs i am able to trace accept for IKE _topo
and IKE but nothing beyond that no drop /encrypt nothing

AUthentication:Hybrid firewall username/password


I have carried out following steps

1)Am able to telnet to fw ike topo port from VPN client machine
2)CLeared the Ipsec and Ike sa (to counter corrupt ike tables)
3)Have checked IKE over tcp enabled
4)The ICA certicate is valid
5)users are valid

Still no luck...the IKE just hangs after the authetication prompt and
ends in "failure to communcate with site x)

Please advise

HELP DEEPLY appreciated

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.