CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SecureClient/SecuRemote
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-21
firewallstarter firewallstarter is offline
Junior Member
 
Join Date: 2008-04-20
Posts: 2
Rep Power: 0
firewallstarter has an average reputation (10+)
Default Phase 2 problems after firewall failover

I am having a problem using Secure Client on a High Availablility pair of Nokia firewalls running VRRP. Everything works fine when I failover to the backup firewall the transition is smooth and the state is preserved. I don't drop a packet. After 60 mins however all Secure Client connections have dropped. ie when they try to renegotiate phase 2 they fail. It looks like the back up firewall can't handle things when the key is rotated after 60 mins.

I see error messages in the log like this.

encryption failure: Unknown SPI: 0xa051f477 for UDP encapsulated IPsec packet.
encryption fail reason: Packet is dropped because an IPsec SA associated with the SPI on the received IPsec packet could not be found



NAT Tracersal mechanism (UDP Encapsulation) Allocated port: VPN1_IPSEC_encapsulation for Remote Access connections is set. The Secure Clients are not behind any NAT devices

FIrewall builds are Check Point VPN-1(TM) & FireWall-1(R) NGX (R61) HFA_02, Hotfix 602 - Build 022
kernel: NGX (R61) HFA_02, Hotfix 602 - Build 022
running on Nokia IPSO 4.1-BUILD022
IP390s Hard Disk based

The management servers are on Check Point VPN-1(TM) & FireWall-1(R) NGX (R65) HFA_02, Hotfix 602 - Build 006
on Check Point SecurePlatform Pro NGX (R65) Build 123

The Secure Client is R60 HFA02

Any help on this matter would be appreciated.

FWS
Reply With Quote
  #2 (permalink)  
Old 3 Weeks Ago
firewallstarter firewallstarter is offline
Junior Member
 
Join Date: 2008-04-20
Posts: 2
Rep Power: 0
firewallstarter has an average reputation (10+)
Default Re: Phase 2 problems after firewall failover

This issue has been resolved successfully.

The problem was a combination of 2 configuration settings.

1. On the backup firewall the "Accept connections to VRRP IP address" wasn't enabled in IPSO. This should be enabled.

2. On the firewall cluster object the parameter "ike_support_crash_recovery_sr" was set to false. This should be set to true. This setting must be changed through the GUIDBedit tool or through vi.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 15:33.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0