Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Site-to-Site vpn with local ip addresses - Possible?

Status
Not open for further replies.

jamesworthy88

IS-IT--Management
May 4, 2004
24
0
0
US
I have a Nokia IP40 and a Checkpoint Edge W. My goal is to use the DMZ port on each to setup a vpn connection using local ip addresses (172.16.3.253 & .254/30)

I can't seem to get this working. The vpn wizard establishes the connection but I can't pass traffic between the two lans. When I ping from the Nokia LAN to any ip address on the Edge, the Edge logs show the traffic is blocked because of ip spoofing. I tried adding/editing static routes and I either keep getting the anti-spoofing errors or I get decrypt errors where the Edge is not expecting the traffic to be coming in over the vpn connection.

The lan on the Nokia is 192.168.10.0/24 and the lan on the Edge is 172.16.2.0/24. Checkpoint support says I need to add a static route but didn't offer specfic details.

If anyone has done this, please let me know what I am missing.....

Thanks,

jw88
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top