| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Plz help me with this situation I've got: Site1 3DES MD5 SHA1 Group 2 (1024) Support agressive mode Site2 3DES MD5 Group 2 (1024) I have this VPN scenarion in which site 1 has both MD5 and SHA1 checked and in site 2 is only MD5 Checked. Also on Site1 I have Support Agressive Mode while site 2 doesn't have this option checked. While trying to communicate there's an error message relating to IKE Phase1 Security Association (SA) Problems. Could it be because of this configuration mismatch or not ? Thanks a lot ! Robori __________________ CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F |
| |||
| ICMP: Echo Request; ICMP Type: 8; ICMP Code: 0; encryption fail reason: Packed is Dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge. __________________ CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F |
| |||
| Quote:
Cheers __________________ Its all in the documentation. |
| |||
| Now the configuration is equal on both gateways. The're R55 gateways and now both of them have SUpport Agressive Mode turned on and both MD5/SHA1 for integrity. I've changed this on SIte2 to stay the same as Site1 and saved, performed some testes but the error persists. :( __________________ CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F |
![]() |
| Thread Tools | |
| Display Modes | |
| |