I'm using FW1 v4.0 on NT.

I have a SERVER object called NAV-cvp with the following properties:
        host:   firewall (NAV is installed on the FW1 box)
        service:        fw1_cvp

I have RESOURCES objects as follows:
        NAV-ftp:
                Match: *
                Methods: GET & PUT
                Action:
                        Server:  NAV-cvp
                        Read/Write
        NAV-http:
                Connection methods: transparent & proxy
                URI match: wild cards
                Match: http & ftp
                Methods: GET, POST, HEAD, & PUT
                Host = *
                Path = *
                Query = *
                Action:
                        Server:  NAV-cvp
                        Read/Write
        NAV-smtp:
                Mail server:  IP address of internal Exchange server
                Match:
                        Sender = *
                        Recipient = *
                Action2:
                        Don't accept mail larger than 1000KB
                        Server:  NAV-cvp
                        Read/Write
                        Allow Chars = 8-bit

The rule in the rulebase is:

        any     any     ftp-->NAV-ftp           accept  short   gateways
any
                        http-->NAV-http
                        smtp-->NAV-smtp

When I enable the rule, http doesn't work.  I get a "failed to contact
security server" error message.  I haven't tested ftp or smtp yet.

I checked the list archives and didn't find anything that would help me.
Can anyone tell from this information what I am doing wrong?

Thanks, Michelle
_____________________
Michelle Johnston
Network Manager, NHRA
2035 Financial Way
Glendora, CA 91741
phone: 626-914-4761 x256
fax: 626-914-7554
[EMAIL PROTECTED]



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to