CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-13
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default simplified VPN!!! simplified!!!

Nothing simple about them

I keep getting the same bloody error


cannot identify peer for encrypted connection [VPN error code 2]

I have encryption domains
I have setup the 'accept encrypted traffic'

And yet i continually get this error!! - i have setup traditional VPN - no problem! - I have even followed the notes on the PDF doc on the checkpoint web site for simplified VPN

Can anyone tell me what is going on - what does this point to?
Why cant it identify the peer for encrypted connection and what is VPN error code 2?????!?!?!

Thanks - before i throw this SPLAT out the window
If this is simple then i am the queen of bloody sheeba!
Reply With Quote
  #2 (permalink)  
Old 2006-03-13
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: simplified VPN!!! simplified!!!

Do you either have a no-nat rule or within the VPN community have a check in the box for disable NAT within the community?
Reply With Quote
  #3 (permalink)  
Old 2006-03-14
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default Re: simplified VPN!!! simplified!!!

Hi lackie

Yes i have a NONAT rule with both networks in

I have also checked /tried the 'do not NAT inside the tunnel'

A question i have to ask is this

I have 1 management server - that sits behind one of the firewalls
It can see all the other firewalls via a static NAT rule -->outbound on the firewall it sits behind [Private IP address]

The other firewalls see the public IP address on their inbound rules and SIC works fine. As the firewalls use a certificate generated by the management server for siomplified vpn's does that mean that they should also have access to the CRL? could this be a problem? do they need to talk back to the management server? Is the CRL hosted on the managment server?

So many questions - but thanks for any answers that may help!
Reply With Quote
  #4 (permalink)  
Old 2006-03-14
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: simplified VPN!!! simplified!!!

Yes, they will need access to the management station for the certificate. I'm guessing that they are trying to communicate with it on it's private IP address.
Reply With Quote
  #5 (permalink)  
Old 2006-03-15
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default Re: simplified VPN!!! simplified!!!

That could be it

Thanks -

Just another question if poss?

I have SPLAT & windows 2003 running without any HFA's - could this also be an issue, i.e. simplified VPN cert problem - means install latest hotfix?
Reply With Quote
  #6 (permalink)  
Old 2006-03-15
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: simplified VPN!!! simplified!!!

You can see smth in release note for HFA, may be you'll find your problem in it.
I think better use last HFA anyway.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:24.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0