We have our entire internal network defined as being in the encryption domain for remote access use.
We also have a frame connection to a partner that terminates on a server in the encryption domain. We want to replace it with a site-to-site Simplified VPN. They're running a WatchGuard 7.0 Firebox III system.
We got the VPN up and running OK but we have one oddity. We also have a web server on our internal network (in the encryption domain) that is accessible from certain IP addresses on the Internet. It is also used by this partner.
When the partner tries to access the web server from the Internet, the connection is dropped as a cleartext packet in an encrypted connection. If I exclude HTTP from the Simplified Community, it works OK.
It appears that the Remote Access and Site-to-Site encryption domains cannot be separated at all even though the rule that has the "if via" objects in Source and Destination only specifiy a particular IP address.
I was thinking that if the "if via" rule did not specify the IP address of the web server, and it doesn't, then traffic to the web server would not have to go down the tunnel as well. The VPN server and the web server are only one digit different in IP addresses, if that matters.
Can anyone shed some light on whether this behavior is correct? That if traffic originates from a Simplified VPN satellite gateway, then all traffic to any IP contained in the encryption domain must be encrypted even if the rule base does not specify this? R55, by the way.
Thanks,
Ray
_________________________________________________________________ Check out the coupons and bargains on MSN Offers! http://youroffers.msn.com
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
