Hi, we had the same problems.
I found some things you could do that may fix it. 1. Not all DSL ore cable routers are capable of passing VPN stuff (i.e. IKE). 2. Users will have to get a fixed IP behind their router and have to forward every TCP and UDP 500 to this IP. 3. Enable both checkboxes in "Tools" -> "Advanced IKE settings". All those things may fix it. Freundliche Gr��e / Best regards Dirk Mautes 4420 Client-Server-Systeme / LAN / WAN Terex Demag GmbH & Co. KG Dinglerstra�e 24 66482 Zweibr�cken Tel: +49 6332 83 1662 Fax: +49 8332 91011107 [EMAIL PROTECTED] www.terex-cranes.com -----Urspr�ngliche Nachricht----- Von: Marlo Montanaro [mailto:[EMAIL PROTECTED] Gesendet: Sonntag, 11. Januar 2004 03:15 An: [EMAIL PROTECTED] Betreff: [FW-1] Setting Up SecureRemote Behind NAT'd Routers Hi, Can someone point me to a link for setting up SecureRemote users behind these home routers? General links would be fine too. We are using a Nokia IP440 with NG FP3. All of our servers are on a 172.x.x.x network behind the firewall. When SecureRemote users are connected directly to the Internet we have no problems. However, when home users connect behind these small home firewalls, cable routers, etc. (such as the Linksys and D-Link boxes), I'm seeing all kinds of problems and intermittent connections. Occasionally the same thing seems to happen when they travel to other corporate type offices and connect to a "foreign" LAN. They can connect to the VPN but not pass traffic. The most obvious (and most important) is dropped packets from my Exchange 5.5 server. I'm seeing many dropped packets on port 3664 from my Exchange Server to 192.168.1.100 - which is of course the first address in the DHCP pool of a Linksys router. I've searched various archives, Google, etc., and come up with some confusing and outdated information pointing to upgrading the router to the latest firmware- all of the routers in question are at the latest version of firmware. IPSec passthrough is also enabled, etc. although I can't vouch for what firewalls other offices are using. A little more insight would be appreciated... Thanks, Marlo ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
