RE: [Security Firewall] IPSEC Passthrough

"Dunlop, Sean" <Sean.Dunlop-s5/[email protected]> Thu, 13 Oct 2005 15:53:28 +0800
Newsgroups gmane.linux.mandrake.security.firewall
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1129190076-811-922
content-class: urn:content-classes:message
Content-Type: text/plain;
	charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable


I have found most of the required info but much of it refers to masq'd traf=
fic for client to server.

My situation is no masq and either end is Checkpoint NG VPN gateway.

Logging shows dropping of Protocol 50 (ESP) when incoming policy is default=
ed to "drop"

There does not appear to be an ESP protocol in the "add rule" protocol list=
. Is there another name for it or has it been forgotten in this list. How c=
an I implement protocol 50 in a rule.

If I use an accept policy between the checkpoint VPN gateway addresses the =
tunnel works initially and then encrypted traffic stops flowing after an ex=
tended idle period. IKE key exchanges are occurring successfully every 12 h=
ours. Nothing is logged on the MNF2 when the problem occurs, traffic just w=
ont flow until a "shorewall restart" is executed.



-----Original Message-----
From: security-firewall-owner-4qZELD6FgxheH41UXmfQsti2O/[email protected] [mailto:security-firewall-o=
wner-4qZELD6FgxheH41UXmfQsti2O/[email protected]] On Behalf Of Dieter Sch=FCtze
Sent: Tuesday, 11 October 2005 12:44 PM
To: security-firewall-4qZELD6FgxheH41UXmfQsti2O/[email protected]
Subject: Re: [Security Firewall] IPSEC Passthrough

Open your browser, go to google and put this in:
ipsec Port numbers

The you get Pages like this:
http://www.isaserver.org/articles/IPSec_Passthrough.html


Sorry for that. ;-)

You need to open the Ports for IPsec and let them through from one Checkpoi=
nt to the other.


Regards

Dieter

Dunlop, Sean schrieb:
> I have a MNF2 box sitting between 2 Checkpoint NG R55 VPN gateways.
>=20
> What do I need to do to the MNF2 ruleset to allow IPSEC to passthrough?
>=20
>=20
>=20
>=20
> ----------------------------------------------------------------------
> --
>=20
> ____________________________________________________
> Want to buy your Pack or Services from Mandriva?=20
> Go to http://store.mandriva.com
> Join the Club : http://www.mandrivaclub.com=20
> ____________________________________________________







------------=_1129190076-811-922
Content-Type: text/plain; name="message.footer"
Content-Disposition: inline; filename="message.footer"
Content-Transfer-Encoding: quoted-printable

____________________________________________________
Want to buy your Pack or Services from Mandriva?=20
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________

------------=_1129190076-811-922--