Here are the elements you need to perform that configuration

To allow a internal user to establish a Nortel Extranet VPN session through
my FW-1. I have some documentation that says to configure these 3 ports:
UDP 500 for IKE Key Management
IP Protocol 50 for IPSEC Payload Encryption
IP Protocol 51 for IPSEC Authentication Header
To set this up you should authorize the services
 IKE,, AH and ESP.


Christian ALT

Telecom and Logistics Associates
Network and Security Company

Firewall-1 FAQ http://www.tla.ch/TLA/FW/FW1FAQ.html







-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of Ilia
Shapira
Sent: dimanche, 25. janvier 2004 09:31
To: [EMAIL PROTECTED]
Subject: [FW-1] Access to Nortel Contivity VPN behind CP NG


I have a PC behind our CP NG that need to connect to some Nortel Contivity
VPN, Nortel say that I need to open pot 500.
I added a rule to allow IPSEC that include IKE that is port 500 however I
still can't connect?

Anyone have an idea what else do I need to do? Does it have something to do
with the fact that this PC is behind NAT ?

Thank you.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
---
Incoming mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.564 / Virus Database: 356 - Release Date: 19.01.2004

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to