This is a bit of a weird one, at least to me. Firewall-1 NG, FP3 on a Nokia IP440 with IPSO V3.6-FCS6.
Inside network is a private 172.x.x.x network. Using hide NAT to the outside interface. I have a DMZ using a 192.168.x.x network with two static NAT devices, both mail servers, one also serves as our Internet-web proxy server. I had a technician install SecureRemote on a workstation. He had no physical access to the outside network so he plugged the laptop into the LAN (the 172.x.x.x network), fired up the VPN and off he went. All was working. He then rebooted the laptop and SecureRemote was set to NOT start on boot (we have it shut off by default because it causes problems with our Novell client when in the office). After the reboot, the laptop was no longer able to pop mail (POP3), send SMTP mail, or access the Internet via the proxy server- the POP3/SMTP/proxy are all the same box on the DMZ. The firewall logs show only accepted packets. When we change the IP address of the workstation, all is well again. When we get a different workstation and give it the original address of the laptop that had the problem, the problem moves to the new workstation. When the problem is occurring, if we change to the inside DMZ (192.168.x.x) address, instead of the outside static NAT address for mail and proxy services, all works again. It is as if the firewall is saying packets from the particular IP address in question to the external NAT'd IP of the DMZ host go into never-never land. Any thoughts? Marlo ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
