CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 3/8, 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-06-12
Junior Member
 
Join Date: 2009-01-23
Posts: 16
Rep Power: 0
gustave69 has an average reputation (10+)
Default Need Help - Pb Lan2Lan between SplatPRO R65 and Nokia R65

Hi,

I try to set up a VPN tunnel between my chekpoint/splatPRO ( cause Nic drivers ) R65 HFA30 and a Nokia/checkpoint R65 HFA40. All parameters seems to be ok (This is not my first tunnel, i have arround 50 tunnels in parallel, working fine) , but for this one i get " Packet is drop because no valid SA. Refer sk 19423"
My VPN SPLAT is in traditionnal mode and my client's Nokia in Communauty mode
Checkpoint/SPLAT to chekpoint/NOKIA VPNs seems to be a bad idea !!!!

Is anyone got a idea ?

Thanks a lot
Reply With Quote
  #2 (permalink)  
Old 2009-06-12
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 2,344
Rep Power: 7
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Need Help - Pb Lan2Lan between SplatPRO R65 and Nokia R65

Unless it is a route-based VPN (aka VTI) it should work just fine.
Time to look at the IKE & VPN debugs:

vpn debug on
vpn debug ikeon

files will be $FWDIR/log

Remember to turn off the debugs before you fill the harddrive :)
Reply With Quote
  #3 (permalink)  
Old 2009-06-13
Junior Member
 
Join Date: 2009-01-23
Posts: 16
Rep Power: 0
gustave69 has an average reputation (10+)
Default Re: Need Help - Pb Lan2Lan between SplatPRO R65 and Nokia R65

Yes, it should works, but it doesn't ;-(

But, I've got a clue. The renegotiation of IPSec Ike Phase 2 parameter is set to 3600s in both side, but when there is no traffic in the tunnel for a hour, the renegotiation seems not starting ( nothing in log ), so the message "Packet is drop because no valid SA" when try to contact the other side after a hour
When there is traffic in the tunnel , the renegotiation is OK

Is there a way to simulate traffic in the tunnel for renegociation to work ?

Thx à lot
Reply With Quote
  #4 (permalink)  
Old 2009-06-15
Senior Member
 
Join Date: 2007-06-04
Posts: 1,459
Rep Power: 4
mcnallym has an average reputation (10+)
Default Re: Need Help - Pb Lan2Lan between SplatPRO R65 and Nokia R65

If you was community at both ends then could use the Permament Tunnel feature available in the community to do this.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:06.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2