[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW-1] IPSEC VPN hanging: NG
> * From: Marc Chauvin <[email protected]> > * Date: Tue, 19 Feb 2002 02:54:21 +0100 > > For your information: > > After (manually) migrating our Firewall from 4.1 to NG, we > had a lot of > VPN problems. SecuRemote users couldn't use MS Exchange > anymore, and some > other connections were simply dropped by the NG firewall without any > warning in the log viewer, nor in vpnd.elg in debug mode. > > The solution was to allow NG to fragment IPSec packets. This > was done by > using the dbedit command on the management server and editing > the firewall > object using the following command: > > modify network_objects <name_of_fw_obj> ipsec_dont_fragment false > update network_objects <name_of_fw_obj> Marc! I got exactly the same problems, but when I try to use dbedit: -------------------- snip -------------------- bash-2.03# dbedit Enter Server name (ENTER for 'localhost'): Enter User Name: fwadmin Enter User Password: Please enter a command, -h for help or -q to quit: dbedit> modify network_objects deimos ipsec_dont_fragment false failed to get field ipsec_dont_fragment -------------------- snip -------------------- Do you have any idea about this? Thank you again for your patience! Stefan Gasteiger I+K Betrieb (zertifiziert nach DIN EN ISO 9001) InfraServ Gendorf Tel.: +49 8679 7 5599 Fax: +49 8679 7 39 5599 Mobiltel.:E-Mail: [email protected] ================================================= To set vacation, Out Of Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
|