Thanks for your help. --- "Moody, Thomas (Contractor) (DDC)" <[EMAIL PROTECTED]> wrote: > Mr. Technologist, > > Checkpoint is very 'picky' about the networks that > it sees behind the > encryption domain on the Cisco side. This is what I > have done this in the > past and it helps a lot... > > Start with the Cisco PIX setting the internal > networks for both it's network > and the CP-FW's to ANY ANY in the ACL. Now, > initialize the communications > from the Checkpoint side. As long as everything > else is setup correctly > [ie. Lifetime for ISAKMP, IKE, 3DES, MD5, Pre-Shard > Key, etc.] you should > see the Main Mode and then the Quick Mode > Completion. Check your logs and > verify the networks as CheckPoint sees them in the > Quick Mode Completion > portion. Now put the networks into the PIX to match > what the Checkpoint > identically. You should now be able to establish > the tunnel without the ANY > ANY on his PIX side. > > Hope this helps.... > > Thomas G. Moody > Sr. Network Security Guy > > > ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > [ORIGINAL MESSAGE] > > > > � -----Original Message----- > � From: Mailing list for discussion of Firewall-1 > � > [mailto:[EMAIL PROTECTED] > On > � Behalf Of Hi Technologist > � Sent: Thursday, March 04, 2004 10:36 AM > � To: [EMAIL PROTECTED] > � Subject: [FW-1] FW-1 TO PIX Tunnel with NAT > � > � FW-1 4.1 SP5, Sol 2.7 > � > � I have a problem with a src static translation > behind > � FW-1. > � > � I've created a tunnel between fw-1 and pix. > � The net behind FW-1 is 10.10.10.0 > � The nets behind pix are 66.114.189.0 and > 192.168.100.0 > � > � Host 10.10.10.10 needs to access hosts on the > nets > � behind the pix. I need to xlate because there are > � 10.(any) in use behind pix. > � > � I've created xlate rules that looks like this: > � > � Xlate Rule 1 > � src dest serv > � 10.10.10.10 66.114.189.0 any > � 192.168.100.0 > � > � natsrc natdest natserv > � 192.168.100.10 orig orig > � > � Xlate Rule 2 > � src dest serv > � 66.114.189.0 192.168.100.10 any > � 192.168.100.0 > � > � natsrc natdest natserv > � orig 10.10.10.10 orig > � > � I have both pix nets in the pix encrypt domain > and > � 10.10.10.0 net in the fw-1 encrypt domain. > � > � Now my problem: > � > � If a ping from 10.10.10.10 to 66.114.189.1, > encryption > � and xlate src occurs as expected. But if I ping > from > � 10.10.10.10 to 192.168.100.129 an encryption > failure > � occurs and no xlate. > � > � Can anyone help? > � > � __________________________________ > � Do you Yahoo!? > � Yahoo! Search - Find what you're looking for > faster > � http://search.yahoo.com > � > � ================================================= > � To set vacation, Out-Of-Office, or away messages, > � send an email to > [EMAIL PROTECTED] > � in the BODY of the email add: > � set fw-1-mailinglist nomail > � ================================================= > � To unsubscribe from this mailing list, > � please see the instructions at > � http://www.checkpoint.com/services/mailing.html > � ================================================= > � If you have any questions on how to change your > � subscription options, email > � [EMAIL PROTECTED] > � ================================================= > � > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > =================================================
__________________________________ Do you Yahoo!? Yahoo! Search - Find what you�re looking for faster http://search.yahoo.com ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
