CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    Courses Starting (2010) 3/8, 4/12, 5/10, 6/7, 7/12.
2. Save the Date!  CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn, Facebook, and Ning.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2009-07-02
Junior Member
 
Join Date: 2009-03-06
Posts: 4
Rep Power: 0
BrA1nE has an average reputation (10+)
Default Cisco 877 to Nokia Checkpoint IP380

Hi

I am trying to setup a VPN from our Nokia IP380 to a cisco 877 device. The problem I am now having is that from the LAN on the cisco I can ping my internal network to the CP but from my internal LAN behind the CP I cannot ping back to anything behind the Cisco 877.

The cisco config all seems ok and has been checked over by various techies but also I can say the same for the CP.

The errors I am getting on the CP tracker "packets dropped due to invalid SA" also on the key exchange for the cisco it is saying "IKE: Quick Mode Received notification from Peer: no proposal chosen"

I have tried various options found in these and other forumns such as "Disable NAT inside VPN Community" & "Change to 'One VPN tunnel per each pair of host'"

Anyone had any similar problems they have overcome or any advise please?
Reply With Quote
  #2 (permalink)  
Old 2009-07-08
Junior Member
 
Join Date: 2009-03-06
Posts: 4
Rep Power: 0
BrA1nE has an average reputation (10+)
Default Re: Cisco 877 to Nokia Checkpoint IP380

Got this working now was the accesslist on the cisco side which now amended and all working ok
Reply With Quote
  #3 (permalink)  
Old 2009-07-08
Member
 
Join Date: 2007-02-19
Posts: 40
Rep Power: 0
denbesten has an average reputation (10+)
Default Re: Cisco 877 to Nokia Checkpoint IP380

You can also solve this particular problem in SmartCenter by clicking "One VPN tunnel per each pair of hosts" on the "VPN advanced" tab of the gateway object for the Cisco.

As you discovered, this issue comes about when the Checkpoint "VPN Domain" does not match the Cisco "Crypto Map ... match address" (access list 110 in your case).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:41.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2