We have our entire internal network defined as being in the encryption
domain for remote access use.

We also have a frame connection to a partner that terminates on a server in
the encryption domain. We want to replace it with a site-to-site Simplified
VPN. They're running a WatchGuard 7.0 Firebox III system.

We got the VPN up and running OK but we have one oddity. We also have a web
server on our internal network (in the encryption domain) that is accessible
from certain IP addresses on the Internet. It is also used by this partner.

When the partner tries to access the web server from the Internet, the
connection is dropped as a cleartext packet in an encrypted connection. If I
exclude HTTP from the Simplified Community, it works OK.

It appears that the Remote Access and Site-to-Site encryption domains cannot
be separated at all even though the rule that has the "if via" objects in
Source and Destination only specifiy a particular IP address.

I was thinking that if the "if via" rule did not specify the IP address of
the web server, and it doesn't, then traffic to the web server would not
have to go down the tunnel as well. The VPN server and the web server are
only one digit different in IP addresses, if that matters.

Can anyone shed some light on whether this behavior is correct? That if
traffic originates from a Simplified VPN satellite gateway, then all traffic
to any IP contained in the encryption domain must be encrypted even if the
rule base does not specify this? R55, by the way.

Thanks,

Ray

_________________________________________________________________
Check out the coupons and bargains on MSN Offers! http://youroffers.msn.com

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to