| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I am trying to manage a remote VRRP HA pair via a VPN set up with the local Checkpoint firewall. I get errors telling me that the packets are dropped due to a possible replay attack. Any ideas on how to configure the rulebase to remotely manage the VRRP pair? (Using CP NGAI R55 in traditional mode) |
| |||
| Managing a remote firewall through a VPN is a bad idea. If for some reason the VPN goes down you have no way of manageing the remote firewall anymore and usually if the VPN goes down you have to manage it to get it back up but are not going to be able to. The management traffic is encrypted so there isn't any harm in letting it go out clear to the remote firewall. |
![]() |
| Thread Tools | |
| Display Modes | |
| |