CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-29
Junior Member
 
Join Date: 2006-03-29
Posts: 6
Rep Power: 0
Dazar has an average reputation (10+)
Default site-2-site Checkpoint NGX vs. Microsoft ISA 2004

I'm trying to setup a vpn S2S between this machines.
The encrypt tunnel is already up, and i accept connection from the ISA.
but i can't PING from the network behind the NGX to the ISA network.

here is the error msg (ping from NGX to ISA):
-----------------------------------------------------
Number: 8495484
Date: 27Mar2006
Time: 17:53:35
Product: VPN-1 Pro/Express
VPN Feature: IKE
Interface: daemon
Origin: ***-fw (*********)
Type: Log
Action: Reject
Reject Reason: IKE failure
Protocol: ip
Rule: 0 - Implied Rules
Encryption Scheme: IKE
VPN Peer Gateway: **** (********)
Subproduct: VPN
Information: encryption failure: no response from peer
---------------------------------------------
and the accept msg (ping from ISA to NGX)
-----------------------------------------------
Number: 8494161
Date: 27Mar2006
Time: 17:32:36
Product: VPN-1 Pro/Express
VPN Feature: VPN
Interface: eth1
Origin: ***** (*******)
Type: Log
Action: Decrypt
Source: ***** (******)
Destination: ******(192.168.1.248)
Protocol: icmp
Rule: 0 - Implied Rules
Encryption Scheme: IKE
VPN Peer Gateway: ***** (********)
Encryption Methods: ESP: 3DES + SHA1 + PFS
Community: *******
Subproduct: VPN
Information: service_id: icmp-proto
ICMP: Echo Request
ICMP Type: 8
ICMP Code: 0
----------------------------------------------------

Thanks,
Dudu
Reply With Quote
  #2 (permalink)  
Old 2006-04-05
Member
 
Join Date: 2006-04-05
Posts: 86
Rep Power: 3
gladiatorkev has an average reputation (10+)
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

Hi,
I am facing a similar Issue ..!
The only difference is that my CP NGX is installed on a Nortel Networks Swiched Firewall 5111.
I am able to ping from ISA to NGX but not Vice-Versa.

Works Perfectly OK WITH R55..!!!!

Have you tried Changing the Source IP Address Selection Settings in
Gateway-- > VPN ---> LinkSelection---> IP Selection by Remote Peeer &
Gateway-- > VPN ---> LinkSelection---> Source IP Address Settings

By The value is Automatic (main Address)
Have you tried making this manual -- to the external IP Address ?!!!
Lets Discuss ..!
Reply With Quote
  #3 (permalink)  
Old 2006-04-11
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

Check out this article and see if it gives any clues: http://www.isaserver.org/articles/20...ositecpv2.html
Reply With Quote
  #4 (permalink)  
Old 2006-04-13
Member
 
Join Date: 2006-04-05
Posts: 86
Rep Power: 3
gladiatorkev has an average reputation (10+)
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

Hi ,
I have already tried that document and my VPN suing R55 works perfectly OK.!
But when i configure similar settings on NGX R60 the same configration does not work (VPN Tunnel allows one side pING ONLY..!).

There is a new setting in Gateway VPN Properties in NGX ---> Link Selection.
Tried Making it to Maula but still of no Help.

Any Suggestions..!?
Reply With Quote
  #5 (permalink)  
Old 2006-04-13
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

In VPN advanced, try changing to Custom settings > one VPN per each pair of hosts. This has worked in the past with a similar problem.
Reply With Quote
  #6 (permalink)  
Old 2006-04-25
Member
 
Join Date: 2006-04-05
Posts: 86
Rep Power: 3
gladiatorkev has an average reputation (10+)
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

Hi !!
My VPN Worked with the following settings ..!
I defined my VPN in Smartdashboard using Trditional method instead of Simplified Method.

Made two rules in CP
1: Remote LAN --> Local LAN --> Encrypt --> IKE (Properties of IKE Same as in ISA side)

2: Reverse Rule of the above

In ISA defined my Remote end Point , Rules for Incoming and Outgoing as well as ROUTE rule.

Also defined ISA Gateway in CP as an interopearable device.

In my Local Gateway settings made VPN--> ADVANCED-- > Outgoing Interface- > Manual (Using External Interface of Gateway )
Source Address Selection -- > Manual (Using External Interface of Gateway )


The above settings were not available berfore NGX..

I have made a document on the above exercise.
Lemme know if anyone needs any.

Kev

Last edited by gladiatorkev; 2006-04-25 at 01:47.
Reply With Quote
  #7 (permalink)  
Old 2006-09-11
Junior Member
 
Join Date: 2006-09-11
Posts: 8
Rep Power: 0
kranti has an average reputation (10+)
Send a message via Yahoo to kranti
Default Re: site-2-site Checkpoint NGX vs. Microsoft ISA 2004

Hi,
I am facing similar problem when I and creating vpn between ISA 2004 and check point ngx...
Please provide the document created by you.
Thanks;;
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:49.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0