Re: [FW-1] site to site VPN failing with Cisco Pix 515 and 505

2009-06-30 Thread czar
Hi Shiroma, Unfortunately, by setting it the gui alone will not resolve the issue. This is spelled out by cp itself. You have to do it manually via dbedit and changing user.def. For your case, you define it only for a host. You can checkout the syntax on how to define a host only. Checkout

[FW-1] Strange VPN problem

2009-06-30 Thread c0re dumped
Some of networks listed in a obejct group that is applied in Manage Network Objects New Check Point Gateway Topology VPN Domain - Manually Defined are not being passed to my vpn clients. These clients are connecting using office mode. Even when I remove some networks of the group, the same

Re: [FW-1] Strange VPN problem

2009-06-30 Thread Sergio Alvarez
I have seen that some times you have to force the VPN Client to refresh the VPN Topology by recreating the site, especially when doing multiple changes, so I guess you could try that. Also bare in mind that even when by default the VPN Domain for site to site and Remote Access VPNs is the same,

Re: [FW-1] Strange VPN problem

2009-06-30 Thread Alexey Baltacov
1: check if you are not blocking topology update 2: try update site on client 3: check if you are using same encryption domain for both secure client and site2site(Gateway Topology VPN Domain-Set Domain for Remote Access Community) 4: re-create site on client -Original Message- From:

Re: [FW-1] site to site VPN failing with Cisco Pix 515 and 505

2009-06-30 Thread Sergio Alvarez
The default option of one tunnel per subnet pair is the one that complies with IPSec standard and you should not change it when doing VPN against interoperable devices, I read something about that quite a while ago. In fact the same document said the other two options (one tunnel per host pair and

Re: [FW-1] VPN Client 64 bits

2009-06-30 Thread Sergio Alvarez
Actually they released SNX R71, which now adds support for Windows Vista 64 bit. Windows XP 64 bit is still not supported. Regards On Mon, Jun 29, 2009 at 6:21 AM, Alexey Baltacov alex...@office.artnet.co.il wrote: In order to use Endpoint Connect with R65 GW you need to upgrade to HFA40