Hi Aaron, here the solution: Set this property to "true" to sync. outbound IPSec SAs. Set the property "fwha_sync_outbound_sa" in the "properties" set in $FWDIR/conf/objects_5_0.C on the management server to "true" (add the property if it is not there). That would look like: :fwha_sync_outbound_sa (true) Install the policy. You can do this while the firewall is running. You should be able to see the property as you set it in $FWDIR/database/objects.C on the module if the change has been completed successfully.
That should work, so have fun! Please let me know what the status is. Best regards from sunny Vienna, Radu Radu Dragomirescu EDS Austria Core Infrastructure - Network Services Donaucity-Stra�e 11 A-1220 Wien Tel: +43-1-7988440-163 Fax: +43-1-7988440-282 -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Donnerstag, 13. M�rz 2003 01:15 To: [EMAIL PROTECTED] Subject: Re: [FW-1] No Valid SA Come to think of it, it probably was specific to simplified rules. -Aaron -----Original Message----- From: Jason Badry [mailto:[EMAIL PROTECTED] Sent: Wednesday, March 12, 2003 3:49 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] No Valid SA I actually have one tunnel using 3DES/MD5 and two other tunnels using 3DES/SHA1 on NG FP3 and I haven't applied the hotfix yet. All tunnels have been working since I moved to NG ~2 weeks ago, and all are to 3rd party firewalls (Borderware/Sonicwall). I am using traditional rules for my VPNs. .. Jason Badry At 09:39 AM 3/12/2003 -0700, you wrote: >I thought I saw a thread a while back that mentioned that NG FP3 could not >do multiple encryption schemes. So you had to just define 3DES and SHA-1, >or 3DES and MD5. You couldn't have some tunnels doing one, and some doing >another. I don't know if NG FP3 HF-1 fixes this or not. Are you on HF-1? > >-Aaron > >-----Original Message----- >From: Alon Goldberg [mailto:[EMAIL PROTECTED] >Sent: Tuesday, March 11, 2003 4:40 PM >To: [EMAIL PROTECTED] >Subject: [FW-1] No Valid SA > > >Hello, > >I'm having problems establishing a VPN from a 4.1 SP5 module to NG FP3. > >1. Management Module: Windows 2000 Server SP3, CP VPN-1 & FW-1 NG FP3 >HF1, 4.1 Backwards Compat >2. Enforcement Module: Nokia IP330, IPSO 3.6 FCS4, CP VPN-1 & FW-1 NG >FP3 HF1 >3. Enforcement Module: Nokia IP120, IPSO 3.5 FCS8, CP VPN-1 & FW-1 4.1 >SP5 > >I'm managing both Enforcement Modules from the same Management Module. >The NG modules reside on the same network, while the 4.1 module is on >another continent. Error as follows: > >1. IKE: Phase 1 Received Notification from Peer: Client Encryption >Notification >2. encryption failure: no response from peer >3. encryption fail reason: Packet is dropped as there is no valid SA > >Phase One IKE is configured with 3DES and DES enabled, MD5 and SHA-1 >enabled, Pre-Shared Secret. I have attempted both Group 1 and Group 2 >SA, with Aggressive Mode enabled. > >Phase Two ESP is configured with 3DES and MD5. > >After an initial connection I usually see one or two Encrypt packets >from my NG network, and then all packets following are dropped. No >Decrypt logs whatsoever. > >Has anyone experienced any similar problems or can offer some >suggestions? Much appreciated! > >Alon Goldberg >CISSP, CCSE NG, CCNA >Security Administrator >Syscom Consulting Inc. > >================================================= >To set vacation, Out Of Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= > >================================================= >To set vacation, Out Of Office, or away messages, >send an email to [EMAIL PROTECTED] >in the BODY of the email add: >set fw-1-mailinglist nomail >================================================= >To unsubscribe from this mailing list, >please see the instructions at >http://www.checkpoint.com/services/mailing.html >================================================= >If you have any questions on how to change your >subscription options, email >[EMAIL PROTECTED] >================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
