CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-09
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Nokia VPN Tunnel problem

Recently we migrated to Checkpoint on Nokia platform from windows platform.

Everything is working fine except VPN tunnnel.

We have noticed few strange things?

1) When we are trying to establish the Tunnel. Quick mode and aggressive mode is happening between our Internal FW-1 IP and Remote VIP.
Is that normal?

2) We are seeing logs as below.

IKE: Aggressive Mode no shared secret for myself and peer
encryption failure: Error occurred

3) IKE Communication on UDP port 500 is happening between our External VIP and Peers external VIP but response we are getting from peer internal IP.


Could anybody help me in this?

Thanks in advance.

Yogesh
Reply With Quote
  #2 (permalink)  
Old 2007-10-09
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Nokia VPN Tunnel problem

Hi
Well there is no issue with Nokia or windows.Kindly check the Checkpoint settings.
First try unchecking the aggressive mode and quick mode, let the VPN setup goes with default settings.
Second the error that you are getting in logs is due to the VPN phase 1 and phase 2 settings on both sides of the Firewalls.If there is PIX/Cisco router try removing the shared secret on the router/PIX and insert again, also make sure that the preshared secret is also inserted at your side.
I hope the other VPN settings are clear to you.
I hope this will help you.
If you need any help please let me know.
Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-10-09
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

What Version are you running.

Is it all on one box, which IP address are you using as the main address of the box, ie what defined in the gateway object as the IP address.

I would suggest if NGX looking at the Link Selection setting under VPN and set it to be select and then select the external IP address.
Reply With Quote
  #4 (permalink)  
Old 2007-10-10
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

We are having two boxes Nokia boxes with VRRP configured and have separate smartcentre server. Checkpoint version at our end and is R62 and remote end its R55W.

We have this tunnel build on our private network. where we have static routes only for the both end external VIP address. do we need to add routes for the physical interface IP's of Nokia boxes as well? as per my understanding in cluster only External Virtual IP is required for the VPN negotation?
Reply With Quote
  #5 (permalink)  
Old 2007-10-10
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

Link selection is set to "based on the topology". but we tried changing that too but no same result.

Yogesh
Reply With Quote
  #6 (permalink)  
Old 2007-10-10
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,032
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

You will see some traffic from the members address as well so I would add routes to say goto the members via the private network as well.
Reply With Quote
  #7 (permalink)  
Old 2007-10-10
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

Thanks for your valuable suggestions.

Yes, You are right I can see Active firewall physical IP's participating in IKE negotiation's. Also theoretically it is not required to add route for all the physical interfaces.
What's say?

even I can see in smartview tracker that our internal physical interface is completing Quick Mode with remote IP. which is very strange. Anything to do with Nokia configuration.

one more Question I have. In the current setup we have standalone windows firewall at one end and Nokia cluster at other end. We even do not have the route for other end physical IP's but its working fine.
Reply With Quote
  #8 (permalink)  
Old 2007-10-12
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

Anybody having more suggestions on this issue?


Thanks in advance.

Yogesh
Reply With Quote
  #9 (permalink)  
Old 2007-10-22
yogeshpanwar yogeshpanwar is offline
Junior Member
 
Join Date: 2007-09-25
Posts: 6
Rep Power: 0
yogeshpanwar has an average reputation (10+)
Default Re: Nokia VPN Tunnel problem

Hi,
Just to share with you.

We added Internel IP in Topology in remote peer in our firewall and selected that IP in the link selection then tunnel started working.

What was happening reverse traffic was coming from Internal interface of remote peer firewall.

Thanks for your help.

Yogesh
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:37.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0