CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
Senior Member
 
Join Date: 2005-08-12
Posts: 162
Rep Power: 4
roadrunner has an average reputation (10+)
Default Phase 2 IKE Negotiation Fails with Secure Client

Phase 2 IKE Negotiation Fails with Secure Client
When doing a dial-up connection with SecuRemote Client Build 4165 for Win95/98, you may authenticate but not complete the formation of the IPSEC tunnel. The firewall logs show the client completed the user authentication and the key exchange. The client completes phase 1 of the IKE negotiation but does not complete phase 2. Sniffing of the connection shows a fragmented UDP packet at the beginning of Phase two but does not identify a port number. Routers to the network drop the packet as unrelated to any session and incomplete. Problem is only related to Windows 95/98 and possibly ME. ME was not tested.

The IKE negotiation packets cannot be fragmented. On Windows 98 (or 95 with Dial-up Networking 1.3 installed), you can modify the parameters on the Dial-Up Adaptor to prevent this from happening. Set the Packet Size parameter to "High" instead of Auto and reboot.

-- PhoneBoy - 02 Apr 2004


FAQForm
FAQs.Class: SecureClientFAQs, TroubleshootingFAQs
FAQs.OS:
FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:21.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0