CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-18
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default VPN Help - Urgent !!!

Plz help me with this situation I've got:

Site1

3DES

MD5
SHA1

Group 2 (1024)
Support agressive mode

Site2

3DES

MD5

Group 2 (1024)

I have this VPN scenarion in which site 1 has both MD5 and SHA1 checked and in site 2 is only MD5 Checked. Also on Site1 I have Support Agressive Mode while site 2 doesn't have this option checked.

While trying to communicate there's an error message relating to IKE Phase1 Security Association (SA) Problems.
Could it be because of this configuration mismatch or not ?


Thanks a lot !
Robori
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #2 (permalink)  
Old 2007-01-18
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: VPN Help - Urgent !!!

Can you paste the error message?
Reply With Quote
  #3 (permalink)  
Old 2007-01-18
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: VPN Help - Urgent !!!

ICMP: Echo Request; ICMP Type: 8; ICMP Code: 0; encryption fail reason: Packed is Dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge.
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #4 (permalink)  
Old 2007-01-18
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: VPN Help - Urgent !!!

Quote:
Originally Posted by robori View Post
While trying to communicate there's an error message relating to IKE Phase1 Security Association (SA) Problems.
Could it be because of this configuration mismatch or not ?
Absolutely! Ensure that the timing is the same on both sides. Remember, for R60 at least, it's possible that the Gateway Object has different IKE settings then the VPN Community Object, check both. Are both gateways Check Point? FYI I've heard of problems w/Aggressive Mode, you may want to disable it.

Cheers
__________________
Its all in the documentation.
Reply With Quote
  #5 (permalink)  
Old 2007-01-19
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 3
robori has an average reputation (10+)
Default Re: VPN Help - Urgent !!!

Now the configuration is equal on both gateways. The're R55 gateways and now both of them have SUpport Agressive Mode turned on and both MD5/SHA1 for integrity.

I've changed this on SIte2 to stay the same as Site1 and saved, performed some testes but the error persists.

:(
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #6 (permalink)  
Old 2007-01-20
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VPN Help - Urgent !!!

From the command line:

vpn debug ikeon
vpn debug on

then look at the log files in $FWDIR/log and see what they have to say.
Reply With Quote
  #7 (permalink)  
Old 2007-01-29
Junior Member
 
Join Date: 2006-05-16
Location: Poland, wielkopolska, Poznan
Posts: 23
Rep Power: 0
wowtek has an average reputation (10+)
Send a message via Skype™ to wowtek
Default Re: VPN Help - Urgent !!!

You have corretct topology on booth site?

Last edited by wowtek; 2007-01-29 at 15:58.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:36.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0