I have a Checkpoint NG client inside my ASL trying to connect to a Checkpoint Firewall at a client site. I can make a connection when I move the client outside ASL, but when behind the firewall I cannot connect. I used a previous post to define the following services and rules:
Services:
Name Protocol S-Port/Client D-Port/Server
Checkpoint udp 2746 2746
Cisco xout udp 1024:65535 62516
IKE udp 500:500
ESP SPI 256:42949672
Filter Rules:
From (Client) Service To (Server) Action
Internal Network__Cisco xout Broadcast Allow
Internal Network__Checkpoint Any Allow
Internal Network__ISAKMP Any Allow
Internal Network__ESP Any Allow
Remote Network__ISAKMP Internal Network Allow
Remote Network__ISAKMP External_Interface Allow
Remote Network__ESP Internal Network Allow
Internal Network__IKE Remote Network Allow
Remote Network__IKE Internal Network Allow
Any help would be greatly appreciated.
Thanks!
This thread was automatically locked due to age.