Thanks for your help.

--- "Moody, Thomas (Contractor) (DDC)"
<[EMAIL PROTECTED]> wrote:
> Mr. Technologist,
>
> Checkpoint is very 'picky' about the networks that
> it sees behind the
> encryption domain on the Cisco side.  This is what I
> have done this in the
> past and it helps a lot...
>
> Start with the Cisco PIX setting the internal
> networks for both it's network
> and the CP-FW's to ANY ANY in the ACL.  Now,
> initialize the communications
> from the Checkpoint side.  As long as everything
> else is setup correctly
> [ie. Lifetime for ISAKMP, IKE, 3DES, MD5, Pre-Shard
> Key, etc.] you should
> see the Main Mode and then the Quick Mode
> Completion.  Check your logs and
> verify the networks as CheckPoint sees them in the
> Quick Mode Completion
> portion.  Now put the networks into the PIX to match
> what the Checkpoint
> identically.  You should now be able to establish
> the tunnel without the ANY
> ANY on his PIX side.
>
> Hope this helps....
>
> Thomas G. Moody
> Sr. Network Security Guy
>
>
>
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
>
> [ORIGINAL MESSAGE]
>
>
>
> �  -----Original Message-----
> �  From: Mailing list for discussion of Firewall-1
> �
> [mailto:[EMAIL PROTECTED]
> On
> �  Behalf Of Hi Technologist
> �  Sent: Thursday, March 04, 2004 10:36 AM
> �  To: [EMAIL PROTECTED]
> �  Subject: [FW-1] FW-1 TO PIX Tunnel with NAT
> �
> �  FW-1 4.1 SP5, Sol 2.7
> �
> �  I have a problem with a src static translation
> behind
> �  FW-1.
> �
> �  I've created a tunnel between fw-1 and pix.
> �  The net behind FW-1 is 10.10.10.0
> �  The nets behind pix are 66.114.189.0 and
> 192.168.100.0
> �
> �  Host 10.10.10.10 needs to access hosts on the
> nets
> �  behind the pix. I need to xlate because there are
> �  10.(any) in use behind pix.
> �
> �  I've created xlate rules that looks like this:
> �
> �  Xlate Rule 1
> �  src            dest           serv
> �  10.10.10.10    66.114.189.0   any
> �                 192.168.100.0
> �
> �  natsrc         natdest        natserv
> �  192.168.100.10 orig           orig
> �
> �  Xlate Rule 2
> �  src           dest           serv
> �  66.114.189.0  192.168.100.10 any
> �  192.168.100.0
> �
> �  natsrc      natdest        natserv
> �  orig        10.10.10.10    orig
> �
> �  I have both pix nets in the pix encrypt domain
> and
> �  10.10.10.0 net in the fw-1 encrypt domain.
> �
> �  Now my problem:
> �
> �  If a ping from 10.10.10.10 to 66.114.189.1,
> encryption
> �  and xlate src occurs as expected. But if I ping
> from
> �  10.10.10.10 to 192.168.100.129 an encryption
> failure
> �  occurs and no xlate.
> �
> �  Can anyone help?
> �
> �  __________________________________
> �  Do you Yahoo!?
> �  Yahoo! Search - Find what you're looking for
> faster
> �  http://search.yahoo.com
> �
> �  =================================================
> �  To set vacation, Out-Of-Office, or away messages,
> �  send an email to
> [EMAIL PROTECTED]
> �  in the BODY of the email add:
> �  set fw-1-mailinglist nomail
> �  =================================================
> �  To unsubscribe from this mailing list,
> �  please see the instructions at
> �  http://www.checkpoint.com/services/mailing.html
> �  =================================================
> �  If you have any questions on how to change your
> �  subscription options, email
> �  [EMAIL PROTECTED]
> �  =================================================
> �
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================


__________________________________
Do you Yahoo!?
Yahoo! Search - Find what you�re looking for faster
http://search.yahoo.com

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to