Hi Dan, many thanks for your tip! I tried everything as you can imagine and disabling PFS didn't help... I chose now Group 1 for IKE Phase 2 and that seems to help... I found an entry in the CP-knowledgebase (sk2124), but that didn't mach... I tried every group possible :-)
Best regards from sunny Vienna, Radu ------------------------------------- Radu Dragomirescu EDS Austria Core Infrastructure - Network Services Donaucity-Stra�e 11 A-1220 Wien Tel: +43-1-7988440-163 Fax: +43-1-7988440-282 -----Original Message----- From: Dan Hitchcock [mailto:[EMAIL PROTECTED] Sent: Dienstag, 01. April 2003 20:35 To: [EMAIL PROTECTED] Subject: Re: [FW-1] NG - different DH groups I have seen a similar problem most specifically for site-to-site VPNs using PFS. After the upgrade, all VPNs between NG modules and 4.1 modules break ("encrypted method didn't match rule"). A look at the advanced properties of the encrypt rule shows that the upgrade chose group1 as the default DH group for PFS. This is, in my opinion, a very *interesting* choice for a default, since 4.1 uses DH group 2 for PFS (non-configurable). Changing the DH group to group2 or disabling PFS resolves the issue. So, this might not actually have anything to do with your specific issue :(, but will hopefully help somebody out there... Dan Hitchcock CCNP, CCSE+, MCSE Manager - Managed Security Services Breakwater Security Associates, Inc. "Safe Harbor for Your Business" dhitchcock (at) breakwatersecurity (dot) com http://www.breakwatersecurity.com 206-770-0700 x147 work The information contained in this email message may be privileged, confidential and protected from disclosure. If you are not the intended recipient, any dissemination, distribution or copying is strictly prohibited. If you think you have received this email message in error, please email the sender at dhitchcock (at) breakwatersecurity (dot) com -----Original Message----- From: Matthias Leu [mailto:[EMAIL PROTECTED] Sent: Tuesday, April 01, 2003 10:21 AM To: [EMAIL PROTECTED] Subject: Re: [FW-1] NG - different DH groups Hi, is only one DH group enabled or more? I had the situation that with offering two DH groups the VPN didn't work. Maybe it helps, best regards, Matthias http://www.fw-1.de Dragomirescu, Radu wrote: > Hi all, > > I just upgraded from 4.1 SP 5 to NG FP Hotfix2 and all my VPNs seem to have > the same problem: > > "encryption failure. Packet was decrypted with methods which are different > from the methods according to the security policy - Gateway and Peer use > different DH groups" > > Anyone here who already seen that error? The setting for IKE Phase 1 & 2 > seem to be the same... I also often installed the rules and rebooted the > firewalls. Yesterday evening I guessed the problem is solved, but today in > the morning there are the same errors in my log! > > Many thanks in advanced! > Radu -- AERAsec Network Services and Security GmbH Wagenberger Strasse 1 D-85662 Hohenbrunn, Germany http://www.aerasec.de ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
