CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-22
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Not working - VPN between CP and PIX

I need to set up a VPN between out CP Site London and a Cisco PIX Site USA.

1st Scenario

USA (Ua and Ub) need to access 2 servers ( a and b) in London

2nd Scenario

London servers ( a and b) needs to access 2 other server ( U1 and U2 ) in USA

I have created 6 nodes and put nodes a and b into group ab and nodes Ua and Ub into Grp Uab and nodes U1 and U2 into group U12

The following rule base have been set up

source <> dest

Uab <>ab<>xvpn<>svc<>accept
ab<>U12<>xvpn<>svc<>accept

In creating the Interoperable devices for USA FW, I put the groups Uab and U12 into yet another group ( USAgrp) and place this as the vpn domain.

Question 1?

Is this allowed and is it correct?.

This is because I need the FW to work for both set of USA grps.

Question 2?

As at now that the above has been configured with just one group in the VPN domain, the VPN is not being formed at all. I have enabled ping and I can see ping from ab getting to the U12 but being dropped.

What am I doing wrong?

Encryption being used are
IKE - 3DES, MD5
IPSEC - AES128, MD5
IPSEC (Phase 2) - se PFS, Group 2, 1024 bits

Thanks for your help.

Last edited by 1q2w3e; 2006-02-22 at 01:54.
Reply With Quote
  #2 (permalink)  
Old 2006-02-22
Senior Member
 
Join Date: 2006-01-25
Posts: 920
Rep Power: 3
melipla has an average reputation (10+)
Default Re: VPN between CP and PIX

Answer to Question 1: Yes that is good.

Answer to Question 2: Need more information. Is the tunnel being formed or do you see SA errors? Are the pings being encrypted? What is the drop message exactly?
Reply With Quote
  #3 (permalink)  
Old 2006-02-22
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: VPN between CP and PIX

Do you use Cisco samples from http://www.cisco.com/en/US/tech/tk58...800ef796.shtml ?
That one is straight forward.
Reply With Quote
  #4 (permalink)  
Old 2006-02-23
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Re: VPN between CP and PIX

Thanks

The tunnel is not being formed at all.
We are NOT using the traditional mode so on the Checkpint NG FW1/VPN1 AI, there is no where for me to specify that I am connecting to a PIX FW.

I am using a Site to Site Star configuration.

The ping is from a default deny all inthe last rule.

Thanks
Reply With Quote
  #5 (permalink)  
Old 2006-02-23
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: VPN between CP and PIX

Sorry, did you solve the problem? I can't decode you last statements. :)
Reply With Quote
  #6 (permalink)  
Old 2006-02-24
Member
 
Join Date: 2006-02-10
Posts: 37
Rep Power: 0
1q2w3e has an average reputation (10+)
Default Re: VPN between CP and PIX

Thanks

No I still have not solved the problem. What I meant was the ping was being denied and it does not go out through the tunnel at all or cause the vpn tunnel to be formed.

Thanks
Reply With Quote
  #7 (permalink)  
Old 2006-02-24
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: VPN between CP and PIX

I advise you to use Subnet to Subnet encryption rules instead of host to host. This type of rules are easy to maintain and troubleshoot.
Use Access-Lists (or PIX) and rule base on CP to restrict communication to host-to host.

PIX to CP vpn definitely works. A lot of peoples already did it (simplified or traditional mode). Use demo stand to test it. It is not hard to find $500 worth PIX501
What version of PIX you are using?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:40.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0