What is the encryption domain ?
Thanks
Darly
At 03:04 PM 7/11/2000 -0400, Joe Voisin wrote:
>
>Using Hide NAT.
>
>EXTERNAL ANY ANY -> INTERNAL ORIG ORIG
>
>The External IP address is a valid IP address of course...
>
>Joe
>
>> -----Original Message-----
>> From: Darly Coupet [mailto:[EMAIL PROTECTED]]
>> Sent: Tuesday, July 11, 2000 2:56 PM
>> To: Joe Voisin; [EMAIL PROTECTED]
>> Subject: RE: [FW1] VPN - NAT and Encryption
>>
>>
>> Joe,
>>
>> Private Net NAT(hide) --- FW1 ----Internet---- FW1--- NAT(hide)
>> >> Private Net
>>
>>
>> Are you using Hide NAT to the External Interface or other Valid IP ?
>> Is the Encryption/Decryption taking place at the Valid IP or
>> Private Network ?
>> Sould the Encryption domain for each network be the External
>> or Valid IP or
>> the Private Network.
>>
>> This is a FW-1 Gateway VPN-1 to FW-1 Gateway VPN-1
>>
>> Thanks
>>
>> Darly
>>
>> At 02:33 PM 7/11/2000 -0400, Joe Voisin wrote:
>> >I am using IKE with 3DES/MD5 no problem through my LinkSys
>> NAT Router...
>> >Will not work with FWZ encryption. I would also think that
>> your router/NAT
>> >would have to support IPSec to some degree.. even if it's just IPSec
>> >Passthru...
>> >
>> >I haven't played with this with other NAT based routers but
>> I would think
>> >that the same applies...
>> >
>> >> -----Original Message-----
>> >> From: Darly Coupet [mailto:[EMAIL PROTECTED]]
>> >> Sent: Tuesday, July 11, 2000 2:23 PM
>> >> To: "Firewall-1 (E-mail)"@onus.us.checkpoint.com;
>> >> [EMAIL PROTECTED]
>> >> Subject: [FW1] VPN - NAT and Encryption
>> >>
>> >>
>> >>
>> >> Firewallers,
>> >>
>> >> Does Firewall 4.1 support the following configuration?
>> >>
>> >> Private Network NAT --- FW1 ----Internet---- FW1--- NAT
>> >> Private Network
>> >>
>> >> Can I use Hide NAT for each private network?
>> >>
>> >> What is the recommended encryption methods?
>> >>
>> >> Thanks for your comments.
>> >>
>> >> Darly
>> >>
>> >>
>> >> ==============================================================
>> >> ==================
>> >> To unsubscribe from this mailing list, please see the
>> >> instructions at
>> >> http://www.checkpoint.com/services/mailing.html
>> >> ==============================================================
>> >> ==================
>> >>
>> >
>> >
>>
>
>
>===========================================================================
=====
> To unsubscribe from this mailing list, please see the instructions at
> http://www.checkpoint.com/services/mailing.html
>===========================================================================
=====
>
>
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================