Did you install the ruleset on the profile of the Edge?

Lino E. Avila

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Fernando
Hagelsieb
Sent: Jueves, 13 de Octubre de 2005 01:05 p.m.
To: [email protected]
Subject: [FW-1] Question about FW rules on VPN-1 Edge

Hi All:

I have an Smartcenter AI R55 HFA 14 managing two VPN-1 Edge Xseries 
appliances

VPN is working on simplified mode
I'm using communities on the VPN manager, a VPN-1 Gateway is working as 
central, and the VPN-1 Edge boxes are satellite gateways

VPN is working, I can send all traffic trough vpn

BUT , I wan to specify more specific firewall rules about the VPN traffic 
(Not to permit all traffic)
I created a ruleset to the VPN-1 Edge profile and it is downloaded fine, but

all rules regarding to vpn traffic are ignored (so that vpn traffic pass 
without restrictions)

That seems to have a "bypassfw" setting enabled on the VPN configuration, 
but I can't see it.

Is there a way to establish customized ruleset for the VPN traffic?

any ideas are welcome

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to