I have seen a similar problem most specifically for site-to-site VPNs using
PFS.  After the upgrade, all VPNs between NG modules and 4.1 modules break
("encrypted method didn't match rule").  A look at the advanced properties
of the encrypt rule shows that the upgrade chose group1 as the default DH
group for PFS.  This is, in my opinion, a very *interesting* choice for a
default, since 4.1 uses DH group 2 for PFS (non-configurable).  Changing the
DH group to group2 or disabling PFS resolves the issue.

So, this might not actually have anything to do with your specific issue :(,
but will hopefully help somebody out there...

Dan Hitchcock
CCNP, CCSE+, MCSE
Manager - Managed Security Services
Breakwater Security Associates, Inc.
"Safe Harbor for Your Business"
dhitchcock (at) breakwatersecurity (dot) com
http://www.breakwatersecurity.com
206-770-0700 x147 work

The information contained in this email message may be privileged,
confidential and protected from disclosure.  If you are not the intended
recipient, any dissemination, distribution or copying is strictly
prohibited.  If you think you have received this email message in error,
please email the sender at dhitchcock (at) breakwatersecurity (dot) com


-----Original Message-----
From: Matthias Leu [mailto:[EMAIL PROTECTED]
Sent: Tuesday, April 01, 2003 10:21 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] NG - different DH groups


Hi,
is only one DH group enabled or more? I had the situation that with
offering two DH groups the VPN didn't work.
Maybe it helps,
best regards,
Matthias
http://www.fw-1.de

Dragomirescu, Radu wrote:
> Hi all,
>
> I just upgraded from 4.1 SP 5 to NG FP Hotfix2 and all my VPNs seem to
have
> the same problem:
>
> "encryption failure. Packet was decrypted with methods which are different
> from the methods according to the security policy - Gateway and Peer use
> different DH groups"
>
> Anyone here who already seen that error? The setting for IKE Phase 1 & 2
> seem to be the same... I also often installed the rules and rebooted the
> firewalls. Yesterday evening I guessed the problem is solved, but today in
> the morning there are the same errors in my log!
>
> Many thanks in advanced!
> Radu


--
AERAsec Network Services and Security GmbH
Wagenberger Strasse 1
D-85662 Hohenbrunn, Germany
http://www.aerasec.de

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to