Symantec Firewall/VPN newbbie questions

Dear Experts,

I have used two Symantec Firewall/VPN products, one is 200R another is 100R.
I have setup a gateway to gateway vpn connection with
the network behind 200R as 192.168.0.0 and the network behind 100R is 192.168.100.0 just as that illustrated in the symantect document. Now, 192.168.0.* is able to ping/telnet/ssh 192.168.100.*, and 192.168.100.* is able to ping/telnet/ssh 192.168.0.*. but I CAN'T map a network drive at 192.168.0.* to 192.168.100.*, and vise-vista.
I do added the ip and name in the c:\windows\hosts file, but the result is the same -- resource can't be assess, not logged on. should I need to set the two networks under a network to make use of network drive and
network browsing, said 192.168.0.1--192.168.0.124 behind 200R, and 192.168.0.125--192.168.0.254 to behind 100R.
 
Except the above question, I wonder it is possible to have a linux nfs mount between the two networks. I have tried but failed.

Your input is highly appreciated!!
Thanks and Regards!

KC
kcwang7Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
ahoffmannConnect With a Mentor Commented:
Windoze Browsing does not work in routed networks.
You nned to add somthing like:

10.0.0.1   "Domain         \0x1b"   #PRE
#
#      NOTE: Spacing of these entries is imperative. Replace 10.0.0.1 with the
#      IP address of your primary domain controller (PDC), PDCName with the
#      NetBIOS name of your PDC, and Domain with your Windows NT domain name.
#      There must be a total of 20 characters within the quotations (the
#      domain name plus the appropriate number of spaces to pad up to 15
#      characters plus the backslash plus the NetBIOS hex representation of
#      the service type).
# may be testet with:  nbtstat -c

to your hosts file.
Also the firewall must allow ports 137-139 in both directions.

Linux NFS mounts work also if the corresponding ports (2049) are open.
0
 
ahoffmannCommented:
What was wrong/unsufficient with my suggestion?
0
 
kcwang7Author Commented:
Dear ahoffmann,

I think I have to say sorry to you as I never tried
your suggestion after I find out that by using the
ip address, I am able to access the share. And yes,
the NFS mount works but with very slow speed. I would try your suggestions and see if it works, and get back to you. but can U explain why by adding the entry that things will work?

Thank you!
0
Worried about phishing attacks?

90% of attacks start with a phish. It’s critical that IT admins and MSSPs have the right security in place to protect their end users from these phishing attacks. Check out our latest feature brief for tips and tricks to keep your employees off a hackers line!

 
ahoffmannCommented:
M$'s SMB is not routable.
0
 
kcwang7Author Commented:
Dear ahoffmann,

seems that it won't work out by adding the entry in
the VPN client's hosts file. After adding that, I tried
to browse the network, the client can only view itself,
and no others..

Regards,
KC
0
 
ahoffmannCommented:
might be a couple of problems:
  1. is the syntax (spaces in particular) correct in hosts file
  2. is hosts file used at all
  3. are the ports 137 .. 139 open at irewall (both ends)
  4. is the remote network NT-based
0
 
kcwang7Author Commented:
Dear ahoffmann,

It is very kind of you to help me in this issue.
I would try to submit request to the community
support to re-rate your answers.

Thanks and Regards,
KC
0
 
ComTechCommented:
Hello kcwang7, ap per your request in Community Support, the grade has been changed to an A.

Regards,
ComTech
CS Admin @ EE
0
 
ahoffmannCommented:
Thanks for being fair.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.