Hi Chris, that's what I yesterday already done and it helped! I have no idea why and I have no explain for that... Nevertheless, many thanks for you effort!
Best regards from sunny Vienna, Radu -----Original Message----- From: Covington, Chris [mailto:[EMAIL PROTECTED] Sent: Dienstag, 01. April 2003 21:48 To: [EMAIL PROTECTED] Subject: Re: [FW-1] NG - different DH groups I've noticed though, that with NG FP3, when you define an Externally Managed Gateway as version 4.1, in the Traditional Mode configuration properties you can not define the Phase 1 DH Group any other way than Group 2: it's greyed out. Maybe this is a 4.1 compatibility fix they've incorporated in FP3 (or HF1/HF2). I suppose you could configure the encrypt rule in Phase 2 with DH Group 1, however, but that would be a blatant mistake. Chris -----Original Message----- From: Dan Hitchcock [mailto:[EMAIL PROTECTED] Sent: Tuesday, April 01, 2003 2:35 PM To: [EMAIL PROTECTED] Subject: Re: [FW-1] NG - different DH groups I have seen a similar problem most specifically for site-to-site VPNs using PFS. After the upgrade, all VPNs between NG modules and 4.1 modules break ("encrypted method didn't match rule"). A look at the advanced properties of the encrypt rule shows that the upgrade chose group1 as the default DH group for PFS. This is, in my opinion, a very *interesting* choice for a default, since 4.1 uses DH group 2 for PFS (non-configurable). Changing the DH group to group2 or disabling PFS resolves the issue. So, this might not actually have anything to do with your specific issue :(, but will hopefully help somebody out there... Dan Hitchcock CCNP, CCSE+, MCSE Manager - Managed Security Services Breakwater Security Associates, Inc. "Safe Harbor for Your Business" dhitchcock (at) breakwatersecurity (dot) com http://www.breakwatersecurity.com 206-770-0700 x147 work The information contained in this email message may be privileged, confidential and protected from disclosure. If you are not the intended recipient, any dissemination, distribution or copying is strictly prohibited. If you think you have received this email message in error, please email the sender at dhitchcock (at) breakwatersecurity (dot) com -----Original Message----- From: Matthias Leu [mailto:[EMAIL PROTECTED] Sent: Tuesday, April 01, 2003 10:21 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] NG - different DH groups Hi, is only one DH group enabled or more? I had the situation that with offering two DH groups the VPN didn't work. Maybe it helps, best regards, Matthias http://www.fw-1.de Dragomirescu, Radu wrote: > Hi all, > > I just upgraded from 4.1 SP 5 to NG FP Hotfix2 and all my VPNs seem to have > the same problem: > > "encryption failure. Packet was decrypted with methods which are > different from the methods according to the security policy - Gateway > and Peer use different DH groups" > > Anyone here who already seen that error? The setting for IKE Phase 1 & > 2 seem to be the same... I also often installed the rules and rebooted > the firewalls. Yesterday evening I guessed the problem is solved, but > today in the morning there are the same errors in my log! > > Many thanks in advanced! > Radu -- AERAsec Network Services and Security GmbH Wagenberger Strasse 1 D-85662 Hohenbrunn, Germany http://www.aerasec.de ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
