View Single Post
  #4 (permalink)  
Old 2008-08-11
dreambuddy dreambuddy is offline
Junior Member
 
Join Date: 2007-06-12
Posts: 19
Rep Power: 0
dreambuddy has an average reputation (10+)
Default Re: Issues in site-to-site VPN b/w Checkpoint R65 and Netscreen

Thanks msjouw for such a nice resourceful link.

Thanks Tdvit for your reply. We have resolved this issue. The issue was at Netscreen end. That guy has configured PFS at his end in Phase 2 (g2-esp-aes128-sha), which was causing the issue.
Since Smartview tracker showed Packet Encrypted once while initially testing the connectivity. This is when we generated traffic from our end and tunnel used to come always when Netscreen guy used to generate traffic from his end. So we derived the conclusion that something to do with the subnet proposal only. But netscreen screen logs used to show correct remote proxy IDs ( my ENcryption domain).
While we used to get notification for Quick Mode Packet 1 from peer as " No Proposal Chosen", but just like that we didn't tallied parameters as we thought that tunnel used to come when other guy is generating traffic, hence parameters would not be an issue. This assumption delayed the troubleshooting.

Regards.
-=KIK=-
Reply With Quote