Was able to get a VPN tunnel up and running between the SSG and Checkpoint, one last problem is that i can't get bi-directional access. Can access computers in trust zone from untrusted but can't access untrusted computers from trusted zone. Can't ping anything in untrusted zone. Noticed in routing entries on the SSG their is nothing for the subnet of the untrusted zone for 192.168.10.0. Added a route to the subnet and not shows this for routing:
login as: netscreen
netscreen@192.168.2.1's password:
Remote Management Console
ssg5-serial-> get routew
^--------unknown keyword routew
ssg5-serial-> get route
IPv4 Dest-Routes for <untrust-vr> (0 entries)
-------------------------------------------------------------------------------- ------
H: Host C: Connected S: Static A: Auto-Exported
I: Imported R: RIP P: Permanent 😧 Auto-Discovered
N: NHRP
iB: IBGP eB: EBGP O: OSPF E1: OSPF external type 1
E2: OSPF external type 2 trailing B: backup route
IPv4 Dest-Routes for <trust-vr> (9 entries)
-------------------------------------------------------------------------------- ------
ID IP-Prefix Interface Gateway P Pref Mtr Vsys
-------------------------------------------------------------------------------- ------
* 6 10.1.1.1/32 eth0/4 0.0.0.0 H 0 0 Root
2 192.168.3.5/32 eth0/0 0.0.0.0 H 0 0 Root
* 8 192.168.2.5/32 bgroup0 0.0.0.0 H 0 0 Root
4 192.168.20.1/32 eth0/1 0.0.0.0 H 0 0 Root
3 192.168.20.0/24 eth0/1 0.0.0.0 C 0 0 Root
1 192.168.3.0/24 eth0/0 0.0.0.0 C 0 0 Root
* 7 192.168.2.0/24 bgroup0 0.0.0.0 C 0 0 Root
* 18 192.168.10.0/24 n/a untrust-vr S 20 1 Root
* 5 10.1.1.0/24 eth0/4 0.0.0.0 C 0 0 Root
get route for 192.168.10.0 shows this:
ssg5-serial-> get route ip 192.168.10.1
Dest for 192.168.10.1
--------------------------------------------------------------------------------------
trust-vr : => 192.168.10.0/24 (id=18) via (vr: untrust-vr), metric 1
none
This can't be right as I still can't ping anything in 192.168.10.0.
When the route was added in the Webui, it was specified as eth0/4, not sure why it shows up as n/a in the route table with untrust-vr as gateway.