CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-06
Junior Member
 
Join Date: 2007-08-29
Posts: 12
Rep Power: 0
mheldens has an average reputation (10+)
Default Encryption failure

Hello,
I have a problem to connect 2 site's together.
I will include a drawing wich makes thing more clear.

A remote location's is connected with a site 2 site VPN connection over the internet. In this location is PC A. At the main site is PC B located and both PC's can connect transparant. At another location is PC C located, this location is behind another CP what is not managed by me. This CP is connected through a private ethernetlink.
The problem occures when PC A whats to ping to PC C. In my CP i get the message "encryption failure: According to the policy the packet should not have been decrypted"
When PC B pings to PC C it's works without errors.
Does anyone hase a clue what i'm doing wrong??

Thanks

Maarten Heldens

Reply With Quote
  #2 (permalink)  
Old 2007-09-06
Senior Member
 
Join Date: 2007-06-04
Posts: 1,070
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Encryption failure

Loking at it then I would guess that you have setup so that the VPN is between Gateway A and Gateway B.

In order to get to Gateway C then you need to traverse Gateway B. Do you run a VPN between A and C or have you configured so that the VPN between A and B also covers the network behind Gateway C. ie the Encryption domain for Gateway B covers the network at Gateway C.

Gateway B to C is clear so no VPN required which is why working fine.
Reply With Quote
  #3 (permalink)  
Old 2007-09-06
Junior Member
 
Join Date: 2007-08-29
Posts: 12
Rep Power: 0
mheldens has an average reputation (10+)
Default Re: Encryption failure

Quote:
Originally Posted by mcnallym View Post
Loking at it then I would guess that you have setup so that the VPN is between Gateway A and Gateway B.

In order to get to Gateway C then you need to traverse Gateway B. Do you run a VPN between A and C or have you configured so that the VPN between A and B also covers the network behind Gateway C. ie the Encryption domain for Gateway B covers the network at Gateway C.

Gateway B to C is clear so no VPN required which is why working fine.
The s2s VPN is between Gateway A and Gateway B. Gateway B covers the network behind Gateway C. Only the netwerk between Gateway B and C (10.31.12.0 /24) is in the encryption domain of Gateway B.
Do i need to place the network of PC C (10.31.15.0 /24) also in the encryption domain of Gateway B???
Reply With Quote
  #4 (permalink)  
Old 2007-09-06
Senior Member
 
Join Date: 2007-07-16
Posts: 618
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Encryption failure

Quote:
Originally Posted by mheldens View Post
The s2s VPN is between Gateway A and Gateway B. Gateway B covers the network behind Gateway C. Only the netwerk between Gateway B and C (10.31.12.0 /24) is in the encryption domain of Gateway B.
Do i need to place the network of PC C (10.31.15.0 /24) also in the encryption domain of Gateway B???
Yes. This needs to be included in the VPN domain.
Reply With Quote
  #5 (permalink)  
Old 2007-09-06
Junior Member
 
Join Date: 2007-08-29
Posts: 12
Rep Power: 0
mheldens has an average reputation (10+)
Default Re: Encryption failure

Quote:
Originally Posted by Thorpuse View Post
Yes. This needs to be included in the VPN domain.
Thanks, i added that subnet to the Encryption domain and i got through CP. Only the other side has to route subnet A backup to me.....but that is out of the scope of this forum.... ;-))

Greetings,

Maarten
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 20:35.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0