I'm also getting this error on a firewall with NGfp3 that has a vpn to a NGfp2 firewall. The vpn is failing amd there are no other vpn's defined. Using simplified mode on both endpoints here.
If we run vpn debug on on the fp2 end we can see: findSAByPeer: Valid ISAKMP SA was not found. me=0, peer=d9ddffd2 but it it tries further on to establish the vpn: [..] [ [EMAIL PROTECTED] GWSupportsMarcipan: Got that this gateway does not support IP A ssignment [..lots of stuff removed here..] vpn_encrypt_invoke: DOING DECRYPTION [ [EMAIL PROTECTED] vpn_decrypt: rule is [ [EMAIL PROTECTED] ISAKMP : ESP: AES-128 + MD5 ; any peer GW [ [EMAIL PROTECTED] vpn_decrypt: clear packet! [ [EMAIL PROTECTED] crypt_pending_add_errorlog: ENTERING [ [EMAIL PROTECTED] crypt_pending_set_error: adding error_msg: Received a cleartext packet within an encrypted connection In the event log of the fp3 gateway we get these error messages: delete_MSA_by_MSPI: ERROR: reference counter is more than 2 fwipsec_free_MSPI_by_methods: ERROR: failed to delete from MSA_by_MSPI And we're unable to send anything either direction in this vpn. Securemote works however fine on both gateways. Lars > -----Original Message----- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] > Sent: Thursday, March 13, 2003 02:15 > To: [EMAIL PROTECTED] > Subject: Re: [FW-1] No Valid SA > > > Come to think of it, it probably was specific to simplified rules. > > -Aaron > > -----Original Message----- > From: Jason Badry [mailto:[EMAIL PROTECTED] > Sent: Wednesday, March 12, 2003 3:49 PM > To: [EMAIL PROTECTED] > Subject: Re: [FW-1] No Valid SA > > > I actually have one tunnel using 3DES/MD5 and two other tunnels using > 3DES/SHA1 on NG FP3 and I haven't applied the hotfix yet. > All tunnels have > been working since I moved to NG ~2 weeks ago, and all are to > 3rd party > firewalls (Borderware/Sonicwall). I am using traditional > rules for my VPNs. > > .. Jason Badry > > > At 09:39 AM 3/12/2003 -0700, you wrote: > >I thought I saw a thread a while back that mentioned that NG > FP3 could not > >do multiple encryption schemes. So you had to just define > 3DES and SHA-1, > >or 3DES and MD5. You couldn't have some tunnels doing one, > and some doing > >another. I don't know if NG FP3 HF-1 fixes this or not. > Are you on HF-1? > > > >-Aaron > > > >-----Original Message----- > >From: Alon Goldberg [mailto:[EMAIL PROTECTED] > >Sent: Tuesday, March 11, 2003 4:40 PM > >To: [EMAIL PROTECTED] > >Subject: [FW-1] No Valid SA > > > > > >Hello, > > > >I'm having problems establishing a VPN from a 4.1 SP5 module > to NG FP3. > > > >1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3 > >HF1, 4.1 Backwards Compat > >2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG > >FP3 HF1 > >3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 > & FW-1 4.1 > >SP5 > > > >I'm managing both Enforcement Modules from the same > Management Module. > >The NG modules reside on the same network, while the 4.1 module is on > >another continent. Error as follows: > > > >1. IKE: Phase 1 Received Notification from Peer: Client Encryption > >Notification > >2. encryption failure: no response from peer > >3. encryption fail reason: Packet is dropped as there is no valid SA > > > >Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1 > >enabled, Pre-Shared Secret. I have attempted both Group 1 > and Group 2 > >SA, with Aggressive Mode enabled. > > > >Phase Two ESP is configured with 3DES and MD5. > > > >After an initial connection I usually see one or two Encrypt packets > >from my NG network, and then all packets following are dropped. No > >Decrypt logs whatsoever. > > > >Has anyone experienced any similar problems or can offer some > >suggestions? Much appreciated! > > > >Alon Goldberg > >CISSP, CCSE NG, CCNA > >Security Administrator > >Syscom Consulting Inc. > > > >================================================= > >To set vacation, Out Of Office, or away messages, > >send an email to [EMAIL PROTECTED] > >in the BODY of the email add: > >set fw-1-mailinglist nomail > >================================================= > >To unsubscribe from this mailing list, > >please see the instructions at > >http://www.checkpoint.com/services/mailing.html > >================================================= > >If you have any questions on how to change your > >subscription options, email > >[EMAIL PROTECTED] > >================================================= > > > >================================================= > >To set vacation, Out Of Office, or away messages, > >send an email to [EMAIL PROTECTED] > >in the BODY of the email add: > >set fw-1-mailinglist nomail > >================================================= > >To unsubscribe from this mailing list, > >please see the instructions at > >http://www.checkpoint.com/services/mailing.html > >================================================= > >If you have any questions on how to change your > >subscription options, email > >[EMAIL PROTECTED] > >================================================= > > ================================================= > To set vacation, Out Of Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > > ================================================= > To set vacation, Out Of Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
