Hi Everyone.
I'm trying to help my users set up a Microsoft Always-On VPN server through a Checkpoint FW.
This is the first time I've tried to publish a server to the internet using CP and R80 so I don't know if i'm doing it wrong or if it's just not working.
I am using R80.30.
I have created my public IP object (from within my internet /26) and configured the NAT which automatically creates the NAT rules. Is this all there is to it to publish a server through the FW?
I have added a policy rule for IKE and IKE-NAT-Traversal from all the internet, as the source, towards the NATted internal IP address as the destination.
Should I see hits on this rule?
I have also configured additional rules for RADIUS traffic from the internal interfaces of the AOVPN RAS servers towards the Microsoft NPS servers.
None of this is working and I don't really know where to look first. We have confirmed using wireshark on the remote client that no reply traffic is being received..
Am I doing it all wrong?