Re: [squid-users] Checkpoint FW1 & Securemote client

From: Neil A. Hillard <hillardn@dont-contact.us>
Date: Thu, 30 May 2002 14:49:27 +0100 (BST)

Wei,

> We have this user whose Securemote client could not authenticate and access
> his intranet webpages through Checkpoint FW. We suspect that our transparent
> proxy might have caused this problem.
Not sure that this is entirely on-topic, but here goes anyway...

> After some debugging, the user is managed to authenticate by using port 900
> (http://x.x.x.x:900/). But, he still could not access his intranet webpages.
> Have you encountered similar problem? Besides removing the user from
> transparent proxy, is there anything we can do to resolve this?
Can you indicate the layout of the network that the user is connecting
over so I can see if your problem is the same as the one I'm experiencing.

You don't happen to be using FWZ Client Encryption and the client is also
going through some NAT or masquerading device ??? If so that may very
well be the cause. Switching to ISAKMP/OAKLEY should help although I'm
waiting to have it confirmed.

Have a look at www.phoneboy.com for similar problems...

HTH,

                                Neil.

-- 
Neil Hillard                    hillardn@whl.co.uk
Westland Helicopters Ltd.       http://www.whl.co.uk/
Disclaimer: This message does not necessarily reflect the
            views of Westland Helicopters Ltd.
Received on Thu May 30 2002 - 08:30:22 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:08:16 MST