CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-19
s_ivanohe s_ivanohe is offline
Junior Member
 
Join Date: 2005-10-06
Posts: 2
Rep Power: 0
s_ivanohe has an average reputation (10+)
Default Gateway not responding secure remote

Hi ,

I have FW on Nokia IP270 with R55 and we try to enable VPN.
using a dial-up connection we had the connection but when we try from DSL cable we have some problem. We obtain always : Gateway not responding and in the checkpoint tracker ( applying the show null matches ) we have thi response :

FWD Error: Log(s) discarded due to unification process failure
FWD Error: Log(s) discarded due to unification process failure
sys_message: too many internal hosts detected

thanks in advice
Reply With Quote
  #2 (permalink)  
Old 2007-12-19
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Gateway not responding secure remote

Quote:
Originally Posted by s_ivanohe View Post
sys_message: too many internal hosts detected
Let's deal with this first. This sounds like a licensing issue. Run this command on your enforcement point:
fw tab -t host_table -s

That command should give you a current value and a peak value of hosts seen by the firewall. Match this with the host count on your license. If over, this can start causing *STRANGE* unexplainable issues (trust me, you don't want to know some of the strange things that we've all seen happen when you are out of license compliance). You can always reboot if it hasn't been booted for a while and it will start the count over.

If you think this may be a licensing issue, talk to your SE and get an eval license and test again. If it all works, you most likely have a licensing issue.


We can help you address the rest after you verify these items.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #3 (permalink)  
Old 2007-12-20
s_ivanohe s_ivanohe is offline
Junior Member
 
Join Date: 2005-10-06
Posts: 2
Rep Power: 0
s_ivanohe has an average reputation (10+)
Default Re: Gateway not responding secure remote

Thanks for the answer. It seems so strange !! the same vpn connection is functioning from a dial-up connection and not from dsl cable. however i have run the command and the results are :
mail[admin]# fw tab -t host_table -s
HOST NAME ID #VALS #PEAK #SLINKS
localhost host_table 8185 143 143 0


I can delete the licence hang on ?
could be that is some miscofiguration of the nokia appliance that don't permit the connection ? it seems that the DSL cable have dynamic IP over a nat and the system can't establish a connection.

thanks again
Reply With Quote
  #4 (permalink)  
Old 2007-12-21
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 277
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Gateway not responding secure remote

Are you licensed for more than 143 hosts on this gateway?
__________________
There's no place like 127.0.0.1
Reply With Quote
  #5 (permalink)  
Old 2007-12-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,627
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Gateway not responding secure remote

IPSec often will not work with DSL as so many of them are PPoE and the MTU is too small. If you use SecureClient and Visitor Mode it should work.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:02.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0