Hello, I'm having problems establishing a VPN from a 4.1 SP5 module to NG FP3.
1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3 HF1, 4.1 Backwards Compat 2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG FP3 HF1 3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 & FW-1 4.1 SP5 I'm managing both Enforcement Modules from the same Management Module. The NG modules reside on the same network, while the 4.1 module is on another continent. Error as follows: 1. IKE: Phase 1 Received Notification from Peer: Client Encryption Notification 2. encryption failure: no response from peer 3. encryption fail reason: Packet is dropped as there is no valid SA Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1 enabled, Pre-Shared Secret. I have attempted both Group 1 and Group 2 SA, with Aggressive Mode enabled. Phase Two ESP is configured with 3DES and MD5. After an initial connection I usually see one or two Encrypt packets from my NG network, and then all packets following are dropped. No Decrypt logs whatsoever. Has anyone experienced any similar problems or can offer some suggestions? Much appreciated! Alon Goldberg CISSP, CCSE NG, CCNA Security Administrator Syscom Consulting Inc. ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
