CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Interoperability
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-31
Senior Member
 
Join Date: 2005-08-30
Posts: 147
Rep Power: 4
tdvit has an average reputation (10+)
Default Checkpoint to Juniper VPN

Hi,

Looking for some help here if I can get it.

Trying to bring up a VPN between NG AI and a Juniper SG Firewall but the Key exchange is failing. Getting a couple of errors.

1. Recieved a cleartext password within an encrypted connection which is weird cause the VPN hasnt come up. This arrow is pointing to the left on this error.

2. encrypt fail reason, packet is dropped cause there was no valid SA. arrow points to the left also with this one.

Any help or thoughts will be greatly recieved.

Mick
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #2 (permalink)  
Old 2008-06-06
Member
 
Join Date: 2008-03-17
Posts: 72
Rep Power: 1
menz456 has an average reputation (10+)
Default Re: Checkpoint to Juniper VPN

I have had so much trouble with this!
Now the main issue is that the proxy id/vpn domain that the checkpoint will send it seems is just a lucky dip.
if you can trouble shoot at the juniper end please type in:
get event type 536
this will show you what proxy id the checkpoint is sending.
you may think that it should send say 192.168.1.1 but it might send
anything. The command from the juniper will show you this and you can
change the policy rule on the juniper to be the same and it'll work.
another big issue is the fact that if you're using a vpn community and using a group for your encryption domain it will not work properly either.
I've been working on this for a while so let me know if you need more help.
sam
Reply With Quote
  #3 (permalink)  
Old 2008-06-06
Senior Member
 
Join Date: 2005-08-30
Posts: 147
Rep Power: 4
tdvit has an average reputation (10+)
Default Re: Checkpoint to Juniper VPN

cheers Sam but got it sorted. the problem was the way the jumiper fwall interfaces are configured and what you pinpoint to use in the vpn.

cheers
__________________
tdvit
CCSA
CCSE
Reply With Quote
  #4 (permalink)  
Old 2008-06-06
Member
 
Join Date: 2008-03-17
Posts: 72
Rep Power: 1
menz456 has an average reputation (10+)
Default Re: Checkpoint to Juniper VPN

Maybe you can help me with a new juniper issue.
We have the vpn up and working and i've just tried to add in another host into the tunnel. The checkpoint end now sends out an id=0.0.0.0??
The Juniper does not like this of course.
I have trawled the net and it may be because i'm now using a group as the vpn domain instead of the network as i was before. Or it might
be the supernetting issue that people talk about.
Have you come across this?
Thanks
Sam
Attached Files
File Type: zip fail.zip (32.9 KB, 8 views)
Reply With Quote
  #5 (permalink)  
Old 2008-06-11
Senior Member
 
Join Date: 2006-11-23
Posts: 159
Rep Power: 3
antonyso88 has an average reputation (10+)
Default Re: Checkpoint to Juniper VPN

What IPSEC Phase 1 and 2 setting. Please try MD5 instead of SHA-1.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:20.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0