I really don't have much experience with FW-1 but do have oodles of knowledge in the area of VPN's. Keep in mind that there is a definite overhead associated with doing a DH exchange at each rekey interval. If the data requires such security it is an appropriate price to pay, but if it does not, it could be quite excessive.
----- Original Message ----- From: "Dragomirescu, Radu" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Tuesday, June 10, 2003 6:47 AM Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem > Hi Aaaron, > > correct, I'm using PFS. I also tried not to use that, but it didn't work. > Then I set the PFS to DH-1 and a miracle happens. > > Radu > > -----Original Message----- > From: Aaron Brasslett [mailto:[EMAIL PROTECTED] > Sent: Dienstag, 10. Juni 2003 14:07 > To: [EMAIL PROTECTED] > Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem > > > Radu, > > Are you using Perfect Forward Secrecy? I thought that DH-2 was necessary > for PFS in 4.1. > > Aaron > > -----Original Message----- > From: Dragomirescu, Radu [mailto:[EMAIL PROTECTED] > Sent: Tuesday, June 10, 2003 1:53 AM > To: [EMAIL PROTECTED] > Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem > > > Hi Aaron, > > I had the same problem and solved that by choosing DH-1 for IKE Phase 2. > Some guys suggested me not to use anyone... That solved not really the > matter, because from time to time I'm loosing the VPN, so I have to reboot > the firewall running on 4.1 for establishing the tunnel. > > Best regards, > Radu > > > -----Original Message----- > From: Aaron Brasslett [mailto:[EMAIL PROTECTED] > Sent: Montag, 09. Juni 2003 20:50 > To: [EMAIL PROTECTED] > Subject: [FW-1] NG to 4.1 Site-to-site VPN Problem > > > Hi all, > > I have a site to site VPN between a Checkpoint 4.1 SP6 firewall on NT4.0 > SP6a and a Nokia IP120 Running Checkpoint NG FP3 IPSO 3.6-FCS3. At > seemingly random times the tunnel between the subnets behind these two > firewalls become inaccessible to each other. Logs on the 4.1 firewall don't > indicate a problem. The NG logs give the entry "Decrypted methods didn't > match rule". Eventually the tunnel will reestablish itself and carry on as > nothing has happened... usually within an hour. I can force the tunnel back > up by issuing a CPRESTART on the NG firewall. I can also force the tunnel > down by installing the policy on the 4.1 firewall. > > I've search thru the archives and have found a few references to this > problem and a couple of suggestions... No suggestions have worked. > > Any ideas? > > Thanks. > > Aaron > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > > ================================================= > To set vacation, Out-Of-Office, or away messages, > send an email to [EMAIL PROTECTED] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, > please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your > subscription options, email > [EMAIL PROTECTED] > ================================================= > > ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
