CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-24
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default encryption failure: Clear text packet should be encrypted

People are not able to connect to a DMZ on my network. This is the error I see on my firewall logs. I am running Checkpoint NGX R60 (hot fix 3)

encryption failure: Clear text packet should be encrypted

Any Clues? Thanks.
__________________
Systems Engineer
Reply With Quote
  #2 (permalink)  
Old 2006-10-24
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: encryption failure: Clear text packet should be encrypted

Are they meant to be connecting via a VPN?

Has this ever worked (and if it has, what has changed recently?)

Have you perhaps recently configured a VPN, such that the firewall is expecting that that traffic should be encrypted?

From where are they connecting? Internally? Externally? Is there any NAT involved?

Some more detail would be nice.
Reply With Quote
  #3 (permalink)  
Old 2006-10-24
Senior Member
 
Join Date: 2006-01-30
Posts: 101
Rep Power: 3
humayun has an average reputation (10+)
Default Re: encryption failure: Clear text packet should be encrypted

No, they are not meant to be connecting via VPN. It was working but after I made a change (completely unrelated) and pushed the policy it stopped working and coming up with that error message.

They are connecting within our Global Network, not our US network.

The VPN that I added does not at all belong to this firewall where the traffic is coming from...So would it still cause this issue?

Thanks again.
__________________
Systems Engineer
Reply With Quote
  #4 (permalink)  
Old 2006-10-24
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: encryption failure: Clear text packet should be encrypted

So you made a change to add a VPN, and since then, this service no longer works?

Follow standard operations procedure. You've made a change. Something has stopped working. Back out the change. Does it work now? If yes, you can conclude that the problem is your change.

If it was me, I would check what you've configured for the encryption domain for this new VPN. My guess is that you've got an overlap between that encryption domain and the network that your other users are coming from.

Remember that I only know what you tell us about your network. In this case, that is the sum of the information in your two posts. I have absolutely no idea what you are referring to by Global or US network. Certainly, obscure IP addresses, but you have to try and give some relevant information - e.g. here, given that you've now got errors referring to encryption problems, might it not have made sense to note that you've made a recent change, a VPN one at that, and that it stopped working when you made the change?
Reply With Quote
  #5 (permalink)  
Old 2006-11-27
Junior Member
 
Join Date: 2006-01-05
Posts: 13
Rep Power: 0
jimytri has an average reputation (10+)
Default Re: encryption failure: Clear text packet should be encrypted

I have client got the same error message like this...

Everytime when this happen, the LAN-2-LAN VPN stop running for the 5-10 seconds.

Jim Qi
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:09.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0