CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default encryption failed: gateway connected to both endpoints

encryption failed: gateway connected to both endpoints



When I have been doing VPN configurations I have seen entries in the log with the following in the info field:



"encryption failed: gateway connected to both endpoints"



The rule this matches looks like this:



Source Destination Service Action Track my-encdomain & partnter-encdomain partnter-encdomain & my-encdomain Any Encrypt Long



The service is typically nb_session or nb_name. Most of them in fact broadcasts generated by the firewall itself.

My setup is the typical VPN setup: the encryption domains are the respective internal networks and in the source and destination fields of the encrypt rule I have a group of all internal networks. Is it something I should worry about? Everything seems to be working OK.

Answer Not only is your encryption rule matching VPN traffic, but it is also matching intranetwork traffic (i.e. within your firewall). When fwd tries to "encrypt" this traffic, it realizes that the source and destination are part of the same encryption domain and thus have the same gateway. This gets logged in the logs as "gateway connected to both endpoints," and is a harmless error.



To avoid this error message, break up the encryption rules as follows:

Source Destination Service Action Track my-encdomain partner-encdomain Any Encrypt Long partnter-encdomain my-encdomain Any Encrypt Long





Source Destination Service Action Track my-encdomain ptnr1-encdom & prntr2-encdom & prtnr3-encdom Any Encrypt Long prtnr1-encdom & prntr2-encdom & prtnr3-encdom my-encdomain Any Encrypt Long

It's also possible to group the partner networks together. You can then name the group CIFSextranet-sites or whatever.

Note: The encryption domains should not overlap.







-- RobertGraham - 14 Jan 2004

FAQForm FAQs.Class: EncryptionFAQs FAQs.OS: FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0