CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-26
Junior Member
 
Join Date: 2005-10-25
Posts: 1
Rep Power: 0
andyproctor has an average reputation (10+)
Default IPSEC SA Error

i'm trying to establish a tunnel between our checkpoint NG+AI to a Juniper/Netscreen firewall.
we have succesfully exchange keys but when i try and access a host on the remote network i see the following error in the cp logs.

"Packet is dropped because there is no valid SA - please refer to solution sk19423 in SecureKnowledge Database for more information"

now because we have key exchange i do not understand this error?
Reply With Quote
  #2 (permalink)  
Old 2005-10-27
Junior Member
 
Join Date: 2005-10-27
Posts: 5
Rep Power: 0
charlesdf23 has an average reputation (10+)
Default Re: IPSEC SA Error

This usually means that your encryption domains don't match up. Ensure that you are both using the same thing. (ie hosts and hosts or network and networks). Sometimes building tunnel's to Cisco products you have to uncheck "key exchange for subnets" in order to establish Phase 2
Reply With Quote
  #3 (permalink)  
Old 2006-03-09
Junior Member
 
Join Date: 2005-11-10
Posts: 17
Rep Power: 0
Huisje has an average reputation (10+)
Default Re: IPSEC SA Error

I was having a problem with a tunnel between a CP FW-1 NG with AI to a Cisco PIX 506E. Traffic from the LAN connected to the PIX to the LAN connected to the CP went through without a problem. The other way arround it was getting blocked by the CP with the "sk19423" error.

Unchecking the "exchange keys for subnets" in the VPN properties of the Interoperable Device fixed it for me. Thanks for the tip!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:42.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0