CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-25
robori robori is offline
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 2
robori has an average reputation (10+)
Default Overlapping encryption domains issue

Hello guys,

I have a site-to-site VPN between one partner company and the Remote Access VPN (SecuRemote) in the same firewall. Itīs running Ngx R60.

Iīve been receiving the error "Packet dropped due to no valid SA" in the logs, the problem is intermitent, and I think itīs because of the way Encryption domains are configured.

In the site-to-site VPN, the remote network is smth like 150.95.132.0/24 and this is configured in the Encryption domain for the firewall. However, in my Remote Access VPN (SecuRemote), thereīs network 150.95.0.0/16 in the Encryption domain. Itīs kindda wierd but itīs setup like this.

Do you think this overlapping encryption domain could be the reason why Iīm getting the Ipsec SA errors ?


Please help me if you have any ideas!


Thanks in advance,
Robori
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #2 (permalink)  
Old 2007-10-26
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Overlapping encryption domains issue

Hi
Well you can try the following resolution, if you are getting the error "packet is dropped as there is no valid SA"
I hope you have access to Secureknowlede, try the resolution sk22752.


I hope that will help you.

Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-10-27
robori robori is offline
Member
 
Join Date: 2006-10-28
Posts: 71
Rep Power: 2
robori has an average reputation (10+)
Default Re: Overlapping encryption domains issue

Thank you! But the thing is that this Site-To-Site VPN is using Shared Secrets instead of Certificates, and itīs working for other source networks just this one is not working.
__________________
CCSE NGX, CCNA, MCSE 2k, LPIc1, ITIL-F
Reply With Quote
  #4 (permalink)  
Old 2007-10-28
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Overlapping encryption domains issue

Hi
Thank you for the informaiton.
Well if you have same network on both sides then it will create the problem of Overlapping domains.
Now the resoluton to this issue you need to create the NATting rules and the dummy networks.
Well there is a resolution at cehckpoint site sk14569
Kindly go through it, I hope it will help you to resolve the issue.
Also read the limitations also.

Regards
ranjit
Reply With Quote
  #5 (permalink)  
Old 2007-10-31
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 131
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Overlapping encryption domains issue

try the command : vpn overlap_encdom on Smart center

Domains are overlaping only if both the gateways on your end and at the remote end participating in the VPN have the same network defined in the VPN domain.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0