Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Checkpoint Secure remote over IOS firewall

Not sure this is the right place to post but I have a client whos having issues with Checkpoint secure remote over IOS based firewall. It does connect but seems to timeout. I'm using dynamic NAT so I dont this its a NAT timeout issue. Anyone got experience of this.

Interestingly I can run Netscreen VPN client (also IPSEC) without issue.

1 REPLY
New Member

Re: Checkpoint Secure remote over IOS firewall

I have found the following out about the FW1 client and you may be able to explain what the INSPECT IPSEC firewall rule on this Cisco is not functioning full and how I may resolve this as per original question:

What I have found regarding Checkpoint is that is uses :

Without NAT

IKE Protocol 500/UDP and 500/TCP

FW-1 topology - 264/TCP

Protocol ESP:50

Protocol FWZ:94

Over NAT

Encapsulated UDP - 2746

Both the Cisco and Netscreen use the following

Without NAT

IKE UDP/500

Protocol ESP:50

Over NAT

Encapsulated UDP 4500 (or 10000)

Could it be the ISPECT ISAKMP is not sufficient?

215
Views
0
Helpful
1
Replies