Come to think of it, it probably was specific to simplified rules.

-Aaron

-----Original Message-----
From: Jason Badry [mailto:[EMAIL PROTECTED]
Sent: Wednesday, March 12, 2003 3:49 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] No Valid SA


I actually have one tunnel using 3DES/MD5 and two other tunnels using
3DES/SHA1 on NG FP3 and I haven't applied the hotfix yet.  All tunnels have
been working since I moved to NG ~2 weeks ago, and all are to 3rd party
firewalls (Borderware/Sonicwall).  I am using traditional rules for my VPNs.

.. Jason Badry


At 09:39 AM 3/12/2003 -0700, you wrote:
>I thought I saw a thread a while back that mentioned that NG FP3 could not
>do multiple encryption schemes.  So you had to just define 3DES and SHA-1,
>or 3DES and MD5.  You couldn't have some tunnels doing one, and some doing
>another.  I don't know if NG FP3 HF-1 fixes this or not.  Are you on HF-1?
>
>-Aaron
>
>-----Original Message-----
>From: Alon Goldberg [mailto:[EMAIL PROTECTED]
>Sent: Tuesday, March 11, 2003 4:40 PM
>To: [EMAIL PROTECTED]
>Subject: [FW-1] No Valid SA
>
>
>Hello,
>
>I'm having problems establishing a VPN from a 4.1 SP5 module to NG FP3.
>
>1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3
>HF1, 4.1 Backwards Compat
>2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG
>FP3 HF1
>3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 & FW-1 4.1
>SP5
>
>I'm managing both Enforcement Modules from the same Management Module.
>The NG modules reside on the same network, while the 4.1 module is on
>another continent.  Error as follows:
>
>1. IKE: Phase 1 Received Notification from Peer: Client Encryption
>Notification
>2. encryption failure: no response from peer
>3. encryption fail reason: Packet is dropped as there is no valid SA
>
>Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1
>enabled, Pre-Shared Secret.  I have attempted both Group 1 and Group 2
>SA, with Aggressive Mode enabled.
>
>Phase Two ESP is configured with 3DES and MD5.
>
>After an initial connection I usually see one or two Encrypt packets
>from my NG network, and then all packets following are dropped.  No
>Decrypt logs whatsoever.
>
>Has anyone experienced any similar problems or can offer some
>suggestions?  Much appreciated!
>
>Alon Goldberg
>CISSP, CCSE NG, CCNA
>Security Administrator
>Syscom Consulting Inc.
>
>=================================================
>To set vacation, Out Of Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================
>
>=================================================
>To set vacation, Out Of Office, or away messages,
>send an email to [EMAIL PROTECTED]
>in the BODY of the email add:
>set fw-1-mailinglist nomail
>=================================================
>To unsubscribe from this mailing list,
>please see the instructions at
>http://www.checkpoint.com/services/mailing.html
>=================================================
>If you have any questions on how to change your
>subscription options, email
>[EMAIL PROTECTED]
>=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to