Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

CheckPoint Client through PIX

We have a company which use the Pix as VPN Server. Now we have to connect an internal PC to CheckPoint FW with the SecureRemote Client.

We sniffered the intern and extern site of the Pix with following results:

the client update to the remote site is ok; we see

IKE pakets inside in both directions.

If we try a ping to a remote server , icmp is encapsulated in UDP with dest 2746, the reply reaches the outside of the PIX but not to the inside.

For testing we opened the access-lists but with no success.

Any suggestions ?

Wolfgang

3 REPLIES
Gold

Re: CheckPoint Client through PIX

New Member

Re: CheckPoint Client through PIX

sorry, I preferre the gateway/gateway connection too.

But the customer requires a VPN connection from the inside PC with the SecureRemote Client through the PIX to a CheckPoint FW.

Thanks

Wolfgang

New Member

Re: CheckPoint Client through PIX

Hi, Just wanted to make sure, is you client behind PAT or static NAT? does the Checkpoint on the other side support NAT-T? what FP is the checkpoint using, you might want to check that.

I would try to give this PC a static NAT translation, and create ACL for it!

87
Views
0
Helpful
3
Replies