cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Problems with 80.10 gateway.

Hi,

I have some difficulties with our new GW 5400 80.10.  

Topology: SMS server (80.20) is behind the 4400 gateway (77.30), static nat. Site-to-site star connection between all gateways.  Center gws 4400 and 5400. 

My SMS server shows "connection with gw is lost", but the.SMS gets FW logs from GW and GW receive politics. Also in the Smart View Tracker, I see CPD protocol with internal SMS IP address as a destination. The SMS successfully receive statuses from other gateways.

The second problem is: Afer push policies to gws all non-checkpoint vpn connections are down and after 5 minutes they are restored. 

In the Tracker I see an error - local interface spoofing. Gateway try to send "esp" to all Interoperable devices from it's external ip, but through the internal interface. I think the root of the problem is such a routing.

Does anyone have any ideas?

Thanks in advice. 

Nick

0 Kudos
4 Replies

Re: Problems with 80.10 gateway.

The second issue seems as the topology is incorrectly defined.

For the first one, can you check if SIC is working? Are both GW and SMS at the same location? Which GW is doing NAT static for SMS? How is ti configured? TO work properly, you need to do automatic NAT, hope that's the case

0 Kudos

Re: Problems with 80.10 gateway.

The first. SIC is working (I've tested it from gw properties). SMS is behind other gw (4400 77.30). 4400 GW is doing automatic static NAT. 5400 is in a remote location and connected to 4400 via site-to-site vpn.

The second. Topology looks right. That interface is defined as internal and security zone is defined as internal. 

0 Kudos

Re: Problems with 80.10 gateway.

On the NAT tab for the SMS object, do you have "Apply for Security Gateway control connections" checked?  You need to if the SMS control traffic is being NATted, also see sk100583: Troubleshooting "SmartCenter behind NAT" issues.

--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com

"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com
0 Kudos

Re: Problems with 80.10 gateway.

Sms does not receive only status from only ONE (5400) gateway. It successfully receives all data from other gateways and receives all data from 5400 except status information.

I believe that problem is on the 5400 (BykGW) side.