CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-02-19
Junior Member
 
Join Date: 2005-12-14
Posts: 21
Rep Power: 0
giulitn has an average reputation (10+)
Default VPN Draytek policy rule

Hi,
I have set up a VPN between a cluster of VPN-1 NGx rR61 with a Draytek router Vigor 2820 (firmware latest 3.3.3).
The VPN is up accoridng with several information I have found on the net but the traffic is not routerd into the VPN.
If I ping from one lan to the main LAN in the headquarter the answer is:
encryption failure: According to the policy the packet should not have been decrypted

Any idea?
Thanks,
bye
Reply With Quote
  #2 (permalink)  
Old 2010-02-19
Senior Member
 
Join Date: 2007-06-04
Posts: 1,560
Rep Power: 5
mcnallym has an average reputation (10+)
Default Re: VPN Draytek policy rule

In the checkpoint interoperable object does the encryption domain behind the draytek gateway overlap with a network at the main office ?
Reply With Quote
  #3 (permalink)  
Old 2010-02-22
Junior Member
 
Join Date: 2005-12-14
Posts: 21
Rep Power: 0
giulitn has an average reputation (10+)
Default Re: VPN Draytek policy rule

Quote:
Originally Posted by mcnallym View Post
In the checkpoint interoperable object does the encryption domain behind the draytek gateway overlap with a network at the main office ?
Thank you for tyhe right question.
I've checked it out and the lan in the headquarter are
10.21/16
172.30.19/24
The LAN behind Drayetk is
10.10.10/24
Reply With Quote
  #4 (permalink)  
Old 2010-02-22
Senior Member
 
Join Date: 2006-10-16
Location: Australia
Posts: 108
Rep Power: 4
godspeedcapri has an average reputation (10+)
Default Re: VPN Draytek policy rule

It looks like a case of subnet overlapping..its lame, but checkpoint has a stringent subnet overlapping check.

I would recommend checking the following:

- In Tracker, pay close attention to Phase II subnet key exchanges - insure that the masks are correctly defined for the internal networks.

- Check the domain object on the checkpoint end and check the internal network/mask object.

Also search CPUG for user.def file modifications. You can specify your local and remote subnet in that file.
__________________
Cheers,
GodSpeedCapri
Reply With Quote
  #5 (permalink)  
Old 2010-03-02
Member
 
Join Date: 2007-02-19
Posts: 69
Rep Power: 4
denbesten has an average reputation (10+)
Default Re: VPN Draytek policy rule

Just ran into the "encryption failure: According to the policy the packet should not have been decrypted" error myself. I had improperly defined the crypto domain for the remote site to not include the source address that they were using. In my case, the error message is basically warning me of anti-spoofing on a VPN level.

To check for this, open the interoperable device object for the dratec, and click on the topology tab. Make sure that the crypto domain includes 10.10.10.0/24.

Also, inspect the log file to verify that the dratec is not doing NAT in a way that you do not expect. If it is, you may need to add its xlate-src address to the crypto-domain. In this case, the trick is to use a network-object group as the crypto domain.

I actually use a group with a name similar to the interoperable device (*-gtwy and *-crypto, actually) whenever I create a VPN because it makes future changes easier.
Reply With Quote
Reply

Tags
vpn drayetk

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:47.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1