CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-24
tekkitan tekkitan is offline
Junior Member
 
Join Date: 2006-03-24
Posts: 1
Rep Power: 0
tekkitan has an average reputation (10+)
Default Site-to-Site VPN with Cisco PIX

We have a customer with an edge box in Europe, that is doing a Site-to-Site VPN to a Cisco PIX here in the states. All of our setting are identicle, except for the VPN domains. They are doing per host VPN, and we are stuck with network. Since the edge only has capability (to our knowledge) to do up to three hosts/networks, this is causing problems we think.

We are seeing the following errors:

Quote:
00029 24Mar2006 15:36:49 Failed to establish VPN Tunnel with ***.***.***.***: no response from peer.
00028 24Mar2006 15:36:13 Failed to establish VPN Tunnel with ***.***.***.***: no proposal chosen
00027 24Mar2006 15:36:13 IKE Phase1: Completed successfully with VPN peer ***.***.***.*** [Security: 3DES/MD5 Expire Time: 23 hour(s), 59 minute(s), 59 second(s) NAT-T: turned off]
00024 24Mar2006 15:34:12 Closed VPN Tunnel with ***.***.***.***
00023 24Mar2006 15:34:12 Failed to establish VPN Tunnel with ***.***.***.***: no proposal chosen
00022 24Mar2006 15:32:50 Failed to establish VPN Tunnel with ***.***.***.***: no response from peer.
00021 24Mar2006 15:32:15 IKE Phase2: Completed successfully with VPN peer ***.***.***.*** [My Ranges: 192.168.10.0-192.168.10.255 Peer Ranges: 172.16.3.97-172.16.3.97 Security: 3DES/SHA1 Expire time: 1 hour(s), 0 second(s) NAT-T: turned off]
00020 24Mar2006 15:32:15 Failed to establish VPN Tunnel with ***.***.***.***: no proposal chosen
00019 24Mar2006 15:32:14 IKE Phase1: Completed successfully with VPN peer ***.***.***.*** [Security: 3DES/MD5 Expire Time: 23 hour(s), 59 minute(s), 59 second(s) NAT-T: turned off]
00018 24Mar2006 15:32:14 ESP ***.***.***.*** [Decryption error] ***.***.***.*** (Safe@Office)
00017 24Mar2006 15:32:14 TCP 192.168.10.254 (DOM-SITE) [TCP out of state] 2046 172.16.3.97 1352 (Lotus Notes)
00016 24Mar2006 15:32:12 Closed VPN Tunnel with ***.***.***.***
00015 24Mar2006 15:32:12 Failed to establish VPN Tunnel with ***.***.***.***: no proposal chosen
00014 24Mar2006 15:30:52 IKE Phase2: Completed successfully with VPN peer ***.***.***.*** [My Ranges: 192.168.10.0-192.168.10.255 Peer Ranges: 172.16.3.97-172.16.3.97 Security: 3DES/SHA1 Expire time: 1 hour(s), 0 second(s) NAT-T: turned off]
00013 24Mar2006 15:30:49 Failed to establish VPN Tunnel with ***.***.***.***: no response from peer.
00012 24Mar2006 15:30:14 Failed to establish VPN Tunnel with ***.***.***.***: no proposal chosen
00011 24Mar2006 15:30:13 IKE Phase1: Completed successfully with VPN peer ***.***.***.*** [Security: 3DES/MD5 Expire Time: 23 hour(s), 59 minute(s), 59 second(s) NAT-T: turned off]
Anyone have any ideas for us? Do you think it's the host based VPN that the Cisco PIX is doing?
Reply With Quote
  #2 (permalink)  
Old 2006-03-25
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: Site-to-Site VPN with Cisco PIX

I advise you to use Network to Network VPN (eg mask /24) and then restrict communication to some /32 hosts. PIX 7.x support assigning filtering access-lists to separate VPN tunnels. Not sure about Safe@
Reply With Quote
  #3 (permalink)  
Old 2006-04-10
jimytri jimytri is offline
Junior Member
 
Join Date: 2006-01-05
Posts: 13
Rep Power: 0
jimytri has an average reputation (10+)
Default Re: Site-to-Site VPN with Cisco PIX

Change IPsec proposal. like ecryption method...

DES, MD5...

some of the PIX, because of licensing problem, it cannot support AES and 3DES...
Reply With Quote
  #4 (permalink)  
Old 2006-06-11
phatgreenbuds phatgreenbuds is offline
Junior Member
 
Join Date: 2006-06-08
Posts: 21
Rep Power: 0
phatgreenbuds has an average reputation (10+)
Default Re: Site-to-Site VPN with Cisco PIX

This is Checkpoint you are dealing with...remember they followed a standard unlike Cisco. Cisco thinks they own the world of networking and they are quite wrong. That being said...since you're trying a site to site tunnel and I see no mention of a manager here you might take a look at the timeout setting for the VPN. Cisco set their default differently then the rest of the industry and CP has always had trouble with VPN's to Cisco unless these are matched up. This would be much easier BTW if you were using the smartcenter to manage the Edge box. That would elimninate the issue of the encryption domain you mentioned and allow you to define as much as you like behind the Edge.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0