CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-20
danzaka danzaka is offline
Junior Member
 
Join Date: 2007-03-05
Posts: 25
Rep Power: 0
danzaka has an average reputation (10+)
Default WTF ?! - EDGE VPN-1 X

has anyone encouter souch a thing when the edge cannot install policy becuase its to BIG ??? ( i have 740 rules and 200 nat`s )
the vpn tunnles wont work due "no proposle chosen"" , as you can see i tried the clock adjustment with no good .

i am on R55 HFA20 ,the VPN-1 is version 7.0.48 ( it had the same problem at version 6 so i tried to update the firmware... no luck there ... )
Lib files are updated ...

here is the log from the edge :

00010 19Sep2007 16:47:48 Failed to install updated security policy
00009 19Sep2007 16:47:48 Error: File size too big or wrong format (size = 429585, maxSize =409599)
00008 19Sep2007 16:47:34 Failed to establish VPN Tunnel with 1.1.11.1: no proposal chosen
00007 19Sep2007 16:47:31 The clock was adjusted from 19Sep2007 16:58:39 to 19Sep2007 16:47:31


Here is the log from the tracker :

Number: 124377
Date: 19Sep2007
Time: 1:32:12
Product: VPN-1 & FireWall-1
Interface: eth0
Origin: FW-Dallas (1.1.1.2)
Type: Log
Action: Accept
Protocol: udp
Service: ISAKMP (500)
Source: 1-1-1-5.static.twtelecom.net (1.1.1.5)
Destination: FW-Dallas (1.1.1.2)
Rule: 0 - Implied Rules
Source Port: ISAKMP (500)
Information: message_info: Implied rule

Number: 124401
Date: 19Sep2007
Time: 1:32:13
Product: VPN-1 & FireWall-1
Interface: daemon
Origin: FW-Dallas (1.1.1.2)
Type: Log
Action: Reject
Reject Reason: IKE failure
Source: 1-1-1-5.static.twtelecom.net (1.1.1.5)
Destination: FW-Dallas (1.11.1.2)
Encryption Scheme: IKE
VPN Peer Gateway: 1-1-1-5.static.twtelecom.net (1.1.1.5)
Information: IKE: Main Mode Missing IKE configuration for peer (authentication or encryption or hash)
Reply With Quote
  #2 (permalink)  
Old 2007-09-20
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: WTF ?! - EDGE VPN-1 X

I'd have to say that if pushing a policy that size to an edge yes it is way too big.

Make sure the policy is only set to install to the Edge the rules that only relevant to the Edge Device.
Reply With Quote
  #3 (permalink)  
Old 2007-09-20
danzaka danzaka is offline
Junior Member
 
Join Date: 2007-03-05
Posts: 25
Rep Power: 0
danzaka has an average reputation (10+)
Default Re: WTF ?! - EDGE VPN-1 X

None of the rules have the edge in the "install on" ...
and i dont have any rules for all gateways or etc...

ohh , except the cleanup rules that are for all gateways
Reply With Quote
  #4 (permalink)  
Old 2007-09-21
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 200
Rep Power: 2
dantro has an average reputation (10+)
Default Re: WTF ?! - EDGE VPN-1 X

Quote:
Originally Posted by danzaka View Post
edge cannot install policy, i have 740 rules and 200 nat`s
None of the rules have the edge in the "install on" ...
?? Do you have 740 rules for the edge or not ??
Is the Edge object a policy installation target in the same policy as for your gateways or did you follow Check Point's recommendation to create a new policy just for the Edge object alone? Please, don't let you ask for these things, tell us what you have set up and we'll tell you what's wrong with it.
Reply With Quote
  #5 (permalink)  
Old 2007-09-21
danzaka danzaka is offline
Junior Member
 
Join Date: 2007-03-05
Posts: 25
Rep Power: 0
danzaka has an average reputation (10+)
Default Re: WTF ?! - EDGE VPN-1 X

sorry for the confusion .

The edge is in the same policy as all the other gateways .
I have a SINGLE huge policy .

So your recommandation is to create a new policiy for the edge devices ?

So there will be one policy for all the SPLAT`s and a second one for all the EDGE devices ?
Reply With Quote
  #6 (permalink)  
Old 2007-09-22
Bob_Zimmerman Bob_Zimmerman is offline
Junior Member
 
Join Date: 2007-03-30
Location: DFW, TX
Posts: 25
Rep Power: 0
Bob_Zimmerman has an average reputation (10+)
Send a message via AIM to Bob_Zimmerman
Default Re: WTF ?! - EDGE VPN-1 X

That's the normal recommendation, yes. Edges have extremely limited memory and storage, so it's a good idea to make a new policy so as to keep everything as efficient as possible.

NAT rules in particular are hard on Edges. Try to do as little translation as possible.
__________________
Robert Zimmerman
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:19.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0