Hello,

I'm having problems establishing a VPN from a 4.1 SP5 module to NG FP3.

1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3
HF1, 4.1 Backwards Compat
2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG
FP3 HF1
3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 & FW-1 4.1
SP5

I'm managing both Enforcement Modules from the same Management Module.
The NG modules reside on the same network, while the 4.1 module is on
another continent.  Error as follows:

1. IKE: Phase 1 Received Notification from Peer: Client Encryption
Notification
2. encryption failure: no response from peer
3. encryption fail reason: Packet is dropped as there is no valid SA

Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1
enabled, Pre-Shared Secret.  I have attempted both Group 1 and Group 2
SA, with Aggressive Mode enabled.

Phase Two ESP is configured with 3DES and MD5.

After an initial connection I usually see one or two Encrypt packets
from my NG network, and then all packets following are dropped.  No
Decrypt logs whatsoever.

Has anyone experienced any similar problems or can offer some
suggestions?  Much appreciated!

Alon Goldberg
CISSP, CCSE NG, CCNA
Security Administrator
Syscom Consulting Inc.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to