Networker and Checkpoint FW

Status
Not open for further replies.

mr.seb

Newcomer
Joined
Mar 28, 2010
Messages
2
Reaction score
0
Points
0
Hello to all

Well I will try to explain my problem.

I'm using a Checkpoint Secure Gateway R70 to secure my servers from internet. There are several interfaces on it. One is for the lan where is my networker 7.5sp2 windows server. other interfaces are for "secure lan".
The ip scope is of course different but on lan there are ad servers and dns resolution is enabled on those secure lan. so ping is permited and nslookup is working fine

Before I had a netbackup server in the same situation and opening some services on chekpoint was ok to backup servers on secure lans

My problem is with Networker :
I have windows servers on this secure lan and i cannot backup them, networker always failed.

The client is correctly defined in nw console keys are valid between them, I can also browse his filesystem. On checkpoint i opened the common range port (even trying full services between both lan/secure lan )

When backup start nw contact the client, i can see in console the differents savesets (c,d, system, vss,...) but nw stop with
39078:save: SYSTEM error client "ip of checkpoint gateway" is not correctly configured on Networker server
5777:save: opening save session impossible with "name of nw server"

??? I don't know how to resolv this
as i said ip ranges are all known from lan dcs, on the networker server I can ping, nslookup, smb, traceroute, ... to secure lan client
and on client do the same to nw server (as I created rules)


Is someone know this and why Networker think my gateway should be a client ?

Thanks if you can help me
 
Check your NAT

Firewall can do NAT if configured.

Use

1) TCPDump or equivalent on your backup client, and
2) Check Point LogViewer

to see what the firewall is actually doing.
 
The problem is resolved, I forgot to add a nat rule on Firewall;)
Original packet : source (dmz lan) destination (networker server) service (any) | Destination packet : source (Original) destination (original) service (original)

Thanks !
 
Status
Not open for further replies.
Back
Top