Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Issue between Cisco 3005 VPN concentrator and Checkpoint

Status
Not open for further replies.

defekt

MIS
Apr 1, 2003
21
US
L2L VPN tunnel. The checkpoint on the other end is doing deep packet inspection (using smart defense) and determining that the traffic is not being natted correctly, therefore blocking the outbound traffic because it might be a reverse route poisoning attack.

I.e.:

1: Syn packet shows tunnel IP address and destination. Packet passes through OK.

2: Ack packet shows return IP tunnel destination AND Internal un-nat'd IP destination (a non-routable 192.168.x.x) and denies the outbound packet because it doesn't match up against a trusted IP.

How do I get my 3005 concentrator to NAT the internal IP Correctly?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top