Have you reloaded the firewall rulebase? And have the SR users updated the
site?

You need to do those, in that order, before SecuRemote will see the updated
encryption domain.

-- 
Timothy Frost                   mailto:[EMAIL PROTECTED]
EDS New Zealand                 Fax: +64-4-495-0473
8 Gilmer Terrace                        Phone: +64-4-495-0504
P O Box 3647
Wellington
New Zealand


-----Original Message-----
From: Tom Sevy [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, January 16, 2001 5:32 AM
To: FWList (E-mail)
Subject: [FW1] SR Encrypt Domain, Subnet question



We have added a new subnet that is not local to the Firewall.  A network
Object has been created for this lan (Class B RFC 1918 172.16.0.0).  And the
firewall (IP440) knows the route to reach this segment.  

The network object has been added the the Encryption Group.

However [using SR on W2K] traffic sent to 172.16.x.x does not go through SR
and goes right out the default router unencrypted.

Did I miss any steps here?  SR can reach everything else that is local to
the FW.



============================================================================
====
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
============================================================================
====


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to