Come to think of it, it probably was specific to simplified rules. -Aaron
-----Original Message----- From: Jason Badry [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 12, 2003 3:49 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] No Valid SA I actually have one tunnel using 3DES/MD5 and two other tunnels using 3DES/SHA1 on NG FP3 and I haven't applied the hotfix yet. All tunnels have been working since I moved to NG ~2 weeks ago, and all are to 3rd party firewalls (Borderware/Sonicwall). I am using traditional rules for my VPNs. .. Jason Badry At 09:39 AM 3/12/2003 -0700, you wrote: >I thought I saw a thread a while back that mentioned that NG FP3 could not >do multiple encryption schemes. So you had to just define 3DES and SHA-1, >or 3DES and MD5. You couldn't have some tunnels doing one, and some doing >another. I don't know if NG FP3 HF-1 fixes this or not. Are you on HF-1? > >-Aaron > >-----Original Message----- >From: Alon Goldberg [mailto:[EMAIL PROTECTED] >Sent: Tuesday, March 11, 2003 4:40 PM >To: [EMAIL PROTECTED] >Subject: [FW-1] No Valid SA > > >Hello, > >I'm having problems establishing a VPN from a 4.1 SP5 module to NG FP3. > >1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3 >HF1, 4.1 Backwards Compat >2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG >FP3 HF1 >3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 & FW-1 4.1 >SP5 > >I'm managing both Enforcement Modules from the same Management Module. >The NG modules reside on the same network, while the 4.1 module is on >another continent. Error as follows: > >1. IKE: Phase 1 Received Notification from Peer: Client Encryption >Notification >2. encryption failure: no response from peer >3. encryption fail reason: Packet is dropped as there is no valid SA > >Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1 >enabled, Pre-Shared Secret. I have attempted both Group 1 and Group 2 >SA, with Aggressive Mode enabled. > >Phase Two ESP is configured with 3DES and MD5. > >After an initial connection I usually see one or two Encrypt packets >from my NG network, and then all packets following are dropped. No >Decrypt logs whatsoever. > >Has anyone experienced any similar problems or can offer some >suggestions? Much appreciated! > >Alon Goldberg >CISSP, CCSE NG, CCNA >Security Administrator >Syscom Consulting Inc. > >================================================= >To set vacation, Out Of Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= > >================================================= >To set vacation, Out Of Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
