CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-27
Stephane Stephane is offline
Junior Member
 
Join Date: 2006-06-27
Posts: 3
Rep Power: 0
Stephane has an average reputation (10+)
Default Site to Site VPN

Hello All,
I have some problems to create a Site to Site VPN trough my Edges Firmware 6.0.74x and my NGX VPN-1.
I have created the object in my Dashboard and add all the information to the VPN object.
I got the error message in the Tracker that told me "no proposal chosen". No VPN is working, only through the "Remote Access Client" mode.

Please, can anybody help me? I need also the steps how to create the site to site VPN in the Dashboard becasue I'm not 100% shure that everything is selected and entered in the right way!

Thank you very much un advanced,
Stephane
Reply With Quote
  #2 (permalink)  
Old 2006-06-27
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Site to Site VPN

Hi,

I ripped the text below the --- from the sofaware.com Knowledge Base. Their KB isn't the best...ok its really quite bad, but it may help.

For our VPN communities that include edge devices, I just used the standard options. In the past w/this no proposal chosen error I've seen that it relates to VPN Properties / Advanced VPN properties of the objects + community. Since edge devices don't have these object settings, I'll gvie you my community ones:

IKE Phase 1: AES-256 / SHA1
IKE Phase 2: AES-128 / MD5
Advanced VPN Prop:
IKE Phase 1: Group 2 (1024 bit)
Reneg 1440 minutes
IKE Phase 2: reneg 3600 secs

All other advanced vpn options are unselected. I'm not on the new firmware so I don't know if that's a problem or not.

---
No proposal chosen error message when creating site to site between Check Point VPN-1 module and Edge device

Answer


A VPN connection between Check Point VPN-1 and an Edge device may fail with error message 'No proposal chosen'. This can happen for the following reasons:

* The VPN-1 Edge gateway object is used in a traditional mode rulebase for the VPN (Encrypt) rule. In order to workaround this, you can use the standard Check Point externally managed gateway object instead of the VPN-1 Edge object.
* IP Compression is enabled for the VPN tunnel on SmartDashboard. The VPN-1 Edge gateway does not support IP compression.
Reply With Quote
  #3 (permalink)  
Old 2006-06-27
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Site to Site VPN

More info from CP's SK:

Edge VPN fails with error "No proposal chosen"

Solution ID: #sk26022

Product: VPN-1 Edge
Version: NG, NG AI
Last Modified: 06-Apr-2005
Symptoms

* VPN between VPN-1 Edge and VPN-1 NG with Application Intelligence R55 using certificates cannot establish tunnel.
* Error: "No proposal chosen" in SmartView Tracker

Cause
Date on VPN-1 Edge device is incorrect, causing certificate to be rejected by remote gateway.
Solution
Set correct date on VPN-1 Edge per sk25955.
Applies To:

* R55
* Site-to-site VPN



+++++++++++++++++++++


Setting date and time on VPN-1 Edge appliance

Solution ID: #sk25955

Product: VPN-1 Edge
Version: NG AI, NG
Last Modified: 06-Apr-2005
Solution
Procedure:

1) In VPN-1 Edge GUI, Select Setup.

2) Go to "Tools".

3) Select "Set Time" button.

4) Then "Set the time manually".

5) Enter correct system Time.

6) Save and Exit.
Applies To:

* R55
* Configuration
Reply With Quote
  #4 (permalink)  
Old 2006-06-28
Stephane Stephane is offline
Junior Member
 
Join Date: 2006-06-27
Posts: 3
Rep Power: 0
Stephane has an average reputation (10+)
Default Re: Site to Site VPN

Hi Melipla,

thank you for your help. I checked both of your replies and had success. The settings are the standard configuration and I took them.
I think the main solution are the time difference between the Edge and the NGX. The VPN is working since I changed it. The funny thing is that I had no problems with the other NG AI firewalls in my network!
Thank you again for your help,
Stephane

Now , I have an other problem. The user from the remote network behind the Edge are able to connect to my network but I can not connect to their network! Any suggestions?
Reply With Quote
  #5 (permalink)  
Old 2006-06-28
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 788
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Site to Site VPN

There could a lot of reasons why it wouldn't make it. Make sure you have GWtoGW rules in place with the proper networks, try some traceroute to see where the traffic actually goes, smartview tracker should give you a good idea of who's dropping the traffic originating from your network to theirs.

HTH
Reply With Quote
  #6 (permalink)  
Old 2006-07-04
Stephane Stephane is offline
Junior Member
 
Join Date: 2006-06-27
Posts: 3
Rep Power: 0
Stephane has an average reputation (10+)
Default Re: Site to Site VPN

Hello Melipla and all others.
I found two solutions during the last working days:
1. If the VPN works only for one of the network sites cause that the certificate on the Edge is damaged. I renewed it and the problem was fixed.
2. The Site to Site VPN worked only perfectly when the Edge object is marked as "Externally Managed Gateway" in the Dashboard. The VPN Site should be created manually in the web interface of the Edge. Use as encryption for example AES256/SHA1. The same should be selected in the Dashboard's VPN community and it works fine.

So, all of my Edges working as Site to Site VPN together with the NGX fine.

Thank you and have a nice day,
Stephane
Reply With Quote
  #7 (permalink)  
Old 2006-10-23
Izzio Izzio is offline
Member
 
Join Date: 2006-04-07
Location: Penzberg, Germany
Posts: 35
Rep Power: 0
Izzio has an average reputation (10+)
Default Re: Site to Site VPN

if the network behind the EDGE is a "trusted" one, than you can set the as managed from your smartcenter and use the "enterprise" VPN profile. This is created automatically inserting the EDGE in a community and pushing the policy on it.
In this way you have central management for the box.

Ciao
Maurizio
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:10.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0