Please note I have the Following problem I am setting up a ipsec tunnel
from a 1700 cisco router to my firewall 

 

The network look like this 

 

10.25.0.0/27---router-----------internet----router-(nat fw internet ip
addrees to internal ) ----(internal -privaterange
)----fw-----172.16.0.0/27.

 

I have checked the the               router config
------------- fw config 

                                                 Crypto isakmp policy1
ike security associations = 30 minutes

 
Renogiate ipsec security associations = 3600 seconds

                                                   Encr 3des

                                                  Hash md5

                                                   Auth pre-share

                                                   Lifetime 1800

                Under cryto map t 1 ipsec-isakmp

               Security asscociation lifetime is 3600

 

In the firwall logs we have the following 

 

Information:                              IKE: Main Mode completion.

IKE: Quick Mode Sent Notification: Responder Lifetime

IKE: Quick Mode completion

IKE IDs: subnet: 172.16.0.0 (mask= 255.255.255.224) and subnet:
10.25.0.0 (mask= 255.255.255.224)

IKE: Informational Exchange Received Delete IPSEC-SA from Peer: d1585ea3

SPIs: ac3bd8b9

IKE: Quick Mode Sent Notification: Responder Lifetime

IKE: Quick Mode completion

IKE IDs: host: 172.16.0.22 and subnet: 10.25.0.0 (mask= 255.255.255.224)

 

 

The rule for fw is client_netw > dmz_network               encrypt ---
slected there router as peer

                           dmz_network< client_netw

 

I see the packets outgoing from our server to there network as encrypt
logs when I try ping but no response. I have

Check the router config and its ok .and the fw config has been checked

It seems as if the there a problem with the ipsec tunnel ??

Can any help

 

The  debug for the router is 

 

 

 

 

Feb 17 23:54:58.901 sat: IPSEC(sa_request): ,

  (key eng. msg.) OUTBOUND local= omitted, remote= omitted,

    local_proxy= 10.25.0.0/255.255.255.224/0/0 (type=4),

    remote_proxy= 172.16.0.0/255.255.255.224/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac ,

    lifedur= 1800s and 4608000kb,

    spi= 0xA92AFA1A(2838166042), conn_id= 0, keysize= 0, flags= 0x400A

Feb 17 23:54:58.905 sat: ISAKMP: received ke message (1/1)

Feb 17 23:54:58.905 sat: ISAKMP (0:0): SA request profile is (NULL)

Feb 17 23:54:58.905 sat: ISAKMP: local port 500, remote port 500

Feb 17 23:54:58.909 sat: ISAKMP: set new node 0 to QM_IDLE

Feb 17 23:54:58.909 sat: ISAKMP: Find a dup sa in the avl tree during
calling isadb_insert sa = 814BBA7C

Feb 17 23:54:58.909 sat: ISAKMP (0:2): Can not start Aggressive mode,
trying Main mode.

Feb 17 23:54:58.909 sat: ISAKMP: Looking for a matching key for omitted
in default : success

Feb 17 23:54:58.909 sat: ISAKMP (0:2): found peer pre-shared key
matching omitted

Feb 17 23:54:58.909 sat: ISAKMP (0:2): constructed NAT-T vendor-03 ID

Feb 17 23:54:58.909 sat: ISAKMP (0:2): constructed NAT-T vendor-02 ID

Feb 17 23:54:58.909 sat: ISAKMP (0:2): Input = IKE_MESG_FROM_IPSEC,
IKE_SA_REQ_MM

Feb 17 23:54:58.913 sat: ISAKMP (0:2): Old State = IKE_READY  New State
= IKE_I_MM1

 

Feb 17 23:54:58.913 sat: ISAKMP (0:2): beginning Main Mode exchange

Feb 17 23:54:58.913 sat: ISAKMP (0:2): sending packet to omitted my_port
500 peer_port 500 (I) MM_NO_STATE

Feb 17 23:54:59.365 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) MM_NO_STATE

Feb 17 23:54:59.365 sat: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER,
IKE_MM_EXCH

Feb 17 23:54:59.369 sat: ISAKMP (0:2): Old State = IKE_I_MM1  New State
= IKE_I_MM2

 

Feb 17 23:54:59.369 sat: ISAKMP (0:2): processing SA payload. message ID
= 0

Feb 17 23:54:59.369 sat: ISAKMP: Looking for a matching key for omitted
in default : success

Feb 17 23:54:59.369 sat: ISAKMP (0:2): found peer pre-shared key
matching omitted

Feb 17 23:54:59.369 sat: ISAKMP (0:2) local preshared key found

Feb 17 23:54:59.369 sat: ISAKMP : Scanning profiles for xauth ...

Feb 17 23:54:59.369 sat: ISAKMP (0:2): Checking ISAKMP transform 1
against priority 1 policy

Feb 17 23:54:59.373 sat: ISAKMP:      encryption 3DES-CBC

Feb 17 23:54:59.373 sat: ISAKMP:      hash MD5

Feb 17 23:54:59.373 sat: ISAKMP:      default group 2

Feb 17 23:54:59.373 sat: ISAKMP:      auth pre-share

Feb 17 23:54:59.373 sat: ISAKMP:      life type in seconds

Feb 17 23:54:59.373 sat: ISAKMP:      life duration (VPI) of  0x0 0x1
0x51 0x80

Feb 17 23:54:59.373 sat: ISAKMP (0:2): atts are acceptable. Next payload
is 0

Feb 17 23:54:59.373 sat: CryptoEngine0: generate alg parameter

Feb 17 23:54:59.373 sat: CryptoEngine0: CRYPTO_ISA_DH_CREATE(hw)(ipsec)

Feb 17 23:54:59.621 sat: CRYPTO_ENGINE: Dh phase 1 status: 0

Feb 17 23:54:59.621 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_MAIN_MODE

Feb 17 23:54:59.621 sat: ISAKMP (0:2): Old State = IKE_I_MM2  New State
= IKE_I_MM2

 

Feb 17 23:54:59.625 sat: ISAKMP (0:2): sending packet to omitted my_port
500 peer_port 500 (I) MM_SA_SETUP

Feb 17 23:54:59.625 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_COMPLETE

Feb 17 23:54:59.625 sat: ISAKMP (0:2): Old State = IKE_I_MM2  New State
= IKE_I_MM3

 

Feb 17 23:55:00.105 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) MM_SA_SETUP

Feb 17 23:55:00.109 sat: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER,
IKE_MM_EXCH

Feb 17 23:55:00.109 sat: ISAKMP (0:2): Old State = IKE_I_MM3  New State
= IKE_I_MM4

 

Feb 17 23:55:00.109 sat: ISAKMP (0:2): processing KE payload. message ID
= 0

Feb 17 23:55:00.109 sat: CryptoEngine0: generate alg parameter

Feb 17 23:55:00.109 sat: CryptoEngine0:
CRYPTO_ISA_DH_SHARE_SECRET(hw)(ipsec)

Feb 17 23:55:00.417 sat: ISAKMP (0:2): processing NONCE payload. message
ID = 0

Feb 17 23:55:00.417 sat: ISAKMP: Looking for a matching key for omitted
in default : success

Feb 17 23:55:00.417 sat: ISAKMP (0:2): found peer pre-shared key
matching omitted

Feb 17 23:55:00.421 sat: CryptoEngine0: create ISAKMP SKEYID for conn id
2

Feb 17 23:55:00.421 sat: CryptoEngine0: CRYPTO_ISA_SA_CREATE(hw)(ipsec)

Feb 17 23:55:00.453 sat: ISAKMP (0:2): SKEYID state generated

Feb 17 23:55:00.453 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_MAIN_MODE

Feb 17 23:55:00.453 sat: ISAKMP (0:2): Old State = IKE_I_MM4  New State
= IKE_I_MM4

 

Feb 17 23:55:00.457 sat: ISAKMP (0:2): Send initial contact

Feb 17 23:55:00.457 sat: ISAKMP (0:2): SA is doing pre-shared key
authentication using id type ID_IPV4_ADDR

Feb 17 23:55:00.457 sat: ISAKMP (2): ID payload

        next-payload : 8

        type         : 1

        addr         : omitted

        protocol     : 17

        port         : 500

        length       : 8

Feb 17 23:55:00.457 sat: ISAKMP (2): Total payload length: 12

Feb 17 23:55:00.457 sat: CryptoEngine0: generate hmac context for conn
id 2

Feb 17 23:55:00.457 sat: CryptoEngine0: CRYPTO_ISA_IKE_HMAC(hw)(ipsec)

Feb 17 23:55:00.465 sat: CryptoEngine0:
CRYPTO_ISA_IKE_ENCRYPT(hw)(ipsec)

Feb 17 23:55:00.469 sat: ISAKMP (0:2): sending packet to omitted my_port
500 peer_port 500 (I) MM_KEY_EXCH

Feb 17 23:55:00.469 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_COMPLETE

Feb 17 23:55:00.469 sat: ISAKMP (0:2): Old State = IKE_I_MM4  New State
= IKE_I_MM5

 

Feb 17 23:55:00.953 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) MM_KEY_EXCH

Feb 17 23:55:00.957 sat: CryptoEngine0:
CRYPTO_ISA_IKE_DECRYPT(hw)(ipsec)

Feb 17 23:55:00.957 sat: ISAKMP (0:2): Input = IKE_MESG_FROM_PEER,
IKE_MM_EXCH

Feb 17 23:55:00.961 sat: ISAKMP (0:2): Old State = IKE_I_MM5  New State
= IKE_I_MM6

 

Feb 17 23:55:00.961 sat: ISAKMP (0:2): processing ID payload. message ID
= 0

Feb 17 23:55:00.961 sat: ISAKMP (0:2): processing HASH payload. message
ID = 0

Feb 17 23:55:00.961 sat: CryptoEngine0: generate hmac context for conn
id 2

Feb 17 23:55:00.961 sat: CryptoEngine0: CRYPTO_ISA_IKE_HMAC(hw)(ipsec)

Feb 17 23:55:00.969 sat: ISAKMP (0:2): processing NOTIFY
RESPONDER_LIFETIME protocol 1

        spi 0, message ID = 0, sa = 814BBA7C

Feb 17 23:55:00.969 sat: ISAKMP (0:2): SA has been authenticated with
omitted

Feb 17 23:55:00.969 sat: ISAKMP (0:2): peer matches *none* of the
profiles

Feb 17 23:55:00.969 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_MAIN_MODE

Feb 17 23:55:00.969 sat: ISAKMP (0:2): Old State = IKE_I_MM6  New State
= IKE_I_MM6

 

Feb 17 23:55:00.973 sat: CryptoEngine0: clear dh number for conn id 1

Feb 17 23:55:00.973 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PROCESS_COMPLETE

Feb 17 23:55:00.973 sat: ISAKMP (0:2): Old State = IKE_I_MM6  New State
= IKE_P1_COMPLETE

 

Feb 17 23:55:00.973 sat: CryptoEngine0: CRYPTO_ISA_DH_DELETE(hw)(ipsec)

Feb 17 23:55:00.977 sat: ISAKMP (0:2): beginning Quick Mode exchange,
M-ID of 567506243

Feb 17 23:55:00.977 sat: CryptoEngine0: generate hmac context for conn
id 2

Feb 17 23:55:00.981 sat: CryptoEngine0: CRYPTO_ISA_IKE_HMAC(hw)(ipsec)

Feb 17 23:55:00.985 sat: CryptoEngine0:
CRYPTO_ISA_IKE_ENCRYPT(hw)(ipsec)

Feb 17 23:55:00.989 sat: ISAKMP (0:2): sending packet to omitted my_port
500 peer_port 500 (I) QM_IDLE

Feb 17 23:55:00.989 sat: ISAKMP (0:2): Node 567506243, Input =
IKE_MESG_INTERNAL, IKE_INIT_QM

Feb 17 23:55:00.989 sat: ISAKMP (0:2): Old State = IKE_QM_READY  New
State = IKE_QM_I_QM1

Feb 17 23:55:00.989 sat: ISAKMP (0:2): Input = IKE_MESG_INTERNAL,
IKE_PHASE1_COMPLETE

Feb 17 23:55:00.993 sat: ISAKMP (0:2): Old State = IKE_P1_COMPLETE  New
State = IKE_P1_COMPLETE

 

Feb 17 23:55:01.049 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) QM_IDLE

Feb 17 23:55:01.053 sat: ISAKMP (0:2): phase 1 packet is a duplicate of
a previous packet.

Feb 17 23:55:01.053 sat: ISAKMP (0:2): retransmitting due to retransmit
phase 1

Feb 17 23:55:01.053 sat: ISAKMP (0:2): retransmitting phase 1 QM_IDLE
...

Feb 17 23:55:01.153 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) QM_IDLE

Feb 17 23:55:01.153 sat: ISAKMP (0:2): phase 1 packet is a duplicate of
a previous packet.

Feb 17 23:55:01.153 sat: ISAKMP (0:2): retransmitting due to retransmit
phase 1

Feb 17 23:55:01.153 sat: ISAKMP (0:2): retransmitting phase 1 QM_IDLE
...

Feb 17 23:55:01.449 sat: ISAKMP (0:2): received packet from omitted
dport 500 sport 500 Global (I) QM_IDLE

Feb 17 23:55:01.449 sat: CryptoEngine0:
CRYPTO_ISA_IKE_DECRYPT(hw)(ipsec)

Feb 17 23:55:01.453 sat: CryptoEngine0: generate hmac context for conn
id 2

Feb 17 23:55:01.453 sat: CryptoEngine0: CRYPTO_ISA_IKE_HMAC(hw)(ipsec)

Feb 17 23:55:01.461 sat: ISAKMP (0:2): processing HASH payload. message
ID = 567506243

Feb 17 23:55:01.461 sat: ISAKMP (0:2): processing SA payload. message ID
= 567506243

Feb 17 23:55:01.461 sat: ISAKMP (0:2): Checking IPSec proposal 1

Feb 17 23:55:01.461 sat: ISAKMP: transform 1, ESP_3DES

Feb 17 23:55:01.461 sat: ISAKMP:   attributes in transform:

Feb 17 23:55:01.461 sat: ISAKMP:      encaps is 1

Feb 17 23:55:01.461 sat: ISAKMP:      SA life type in seconds

Feb 17 23:55:01.461 sat: ISAKMP:      SA life duration (basic) of 1800

Feb 17 23:55:01.461 sat: ISAKMP:      SA life type in kilobytes

Feb 17 23:55:01.465 sat: ISAKMP:      SA life duration (VPI) of  0x0
0x46 0x50 0x0

Feb 17 23:55:01.465 sat: ISAKMP:      authenticator is HMAC-MD5

Feb 17 23:55:01.465 sat: CryptoEngine0: validate proposal

Feb 17 23:55:01.465 sat: ISAKMP (0:2): atts are acceptable.

Feb 17 23:55:01.465 sat: IPSEC(validate_proposal_request): proposal part
#1,

  (key eng. msg.) INBOUND local= omitted, remote= omitted,

    local_proxy= 10.25.0.0/255.255.255.224/0/0 (type=4),

    remote_proxy= 172.16.0.0/255.255.255.224/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac ,

    lifedur= 0s and 0kb,

    spi= 0x0(0), conn_id= 0, keysize= 0, flags= 0x2

Feb 17 23:55:01.469 sat: CryptoEngine0: validate proposal request

Feb 17 23:55:01.469 sat: IPSEC(kei_proxy): head = aptmap, map->ivrf = ,
kei->ivrf =

Feb 17 23:55:01.469 sat: ISAKMP (0:2): processing NONCE payload. message
ID = 567506243

Feb 17 23:55:01.469 sat: ISAKMP (0:2): processing ID payload. message ID
= 567506243

Feb 17 23:55:01.469 sat: ISAKMP (0:2): processing ID payload. message ID
= 567506243

Feb 17 23:55:01.469 sat: ISAKMP (0:2): processing NOTIFY
RESPONDER_LIFETIME protocol 3

        spi 2838166042, message ID = 567506243, sa = 814BBA7C

Feb 17 23:55:01.473 sat: ISAKMP (0:2): processing responder lifetime

Feb 17 23:55:01.473 sat: CryptoEngine0: generate hmac context for conn
id 2

Feb 17 23:55:01.473 sat: CryptoEngine0: CRYPTO_ISA_IKE_HMAC(hw)(ipsec)

Feb 17 23:55:01.477 sat: CryptoEngine0: ipsec allocate flow

Feb 17 23:55:01.481 sat: CryptoEngine0: ipsec allocate flow

Feb 17 23:55:01.481 sat: CryptoEngine0:
CRYPTO_ISA_IPSEC_KEY_CREATE(hw)(ipsec)

Feb 17 23:55:01.505 sat: CryptoEngine0:
CRYPTO_ISA_IPSEC_KEY_CREATE(hw)(ipsec)

Feb 17 23:55:01.533 sat: ISAKMP (0:2): Creating IPSec SAs

Feb 17 23:55:01.533 sat:         inbound SA from omitted to omitted
(f/i)  0/ 0

        (proxy 172.16.0.0 to 10.25.0.0)

Feb 17 23:55:01.533 sat:         has spi 0xA92AFA1A and conn_id 200 and
flags 2

Feb 17 23:55:01.533 sat:         lifetime of 1800 seconds

Feb 17 23:55:01.533 sat:         lifetime of 4608000 kilobytes

Feb 17 23:55:01.533 sat:         has client flags 0x0

Feb 17 23:55:01.533 sat:         outbound SA from omitted   to omitted
(f/i)  0/ 0 (proxy 10.25.0.0       to 172.16.0.0     )

Feb 17 23:55:01.533 sat:         has spi -541287687 and conn_id 201 and
flags A

Feb 17 23:55:01.537 sat:         lifetime of 1800 seconds

Feb 17 23:55:01.537 sat:         lifetime of 4608000 kilobytes

Feb 17 23:55:01.537 sat:         has client flags 0x0

Feb 17 23:55:01.537 sat: CryptoEngine0:
CRYPTO_ISA_IKE_ENCRYPT(hw)(ipsec)

Feb 17 23:55:01.537 sat: IPSEC(key_engine): got a queue event...

Feb 17 23:55:01.537 sat: IPSEC(initialize_sas): ,

  (key eng. msg.) INBOUND local= omitted, remote= omitted,

    local_proxy= 10.25.0.0/255.255.255.224/0/0 (type=4),

    remote_proxy= 172.16.0.0/255.255.255.224/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac ,

    lifedur= 1800s and 4608000kb,

    spi= 0xA92AFA1A(2838166042), conn_id= 200, keysize= 0, flags= 0x2

Feb 17 23:55:01.541 sat: IPSEC(initialize_sas): ,

  (key eng. msg.) OUTBOUND local= omitted, remote= omitted,

    local_proxy= 10.25.0.0/255.255.255.224/0/0 (type=4),

    remote_proxy= 172.16.0.0/255.255.255.224/0/0 (type=4),

    protocol= ESP, transform= esp-3des esp-md5-hmac ,

    lifedur= 1800s and 4608000kb,

    spi= 0xDFBC9AF9(3753679609), conn_id= 201, keysize= 0, flags= 0xA

Feb 17 23:55:01.541 sat: IPSEC(kei_proxy): head = aptmap, map->ivrf = ,
kei->ivrf =

Feb 17 23:55:01.541 sat: IPSEC(add mtree): src 10.25.0.0, dest
172.16.0.0, dest_port 0

 

Feb 17 23:55:01.545 sat: IPSEC(create_sa): sa created,

  (sa) sa_dest= omitted, sa_prot= 50,

    sa_spi= 0xA92AFA1A(2838166042),

    sa_trans= esp-3des esp-md5-hmac , sa_conn_id= 200

Feb 17 23:55:01.545 sat: IPSEC(create_sa): sa created,

  (sa) sa_dest= omitted, sa_prot= 50,

    sa_spi= 0xDFBC9AF9(3753679609),

    sa_trans= esp-3des esp-md5-hmac , sa_conn_id= 201

Feb 17 23:55:01.549 sat: ISAKMP (0:2): sending packet to omitted my_port
500 peer_port 500 (I) QM_IDLE

Feb 17 23:55:01.549 sat: ISAKMP (0:2): deleting node 567506243 error
FALSE reason ""

Feb 17 23:55:01.549 sat: ISAKMP (0:2): Node 567506243, Input =
IKE_MESG_FROM_PEER, IKE_QM_EXCH

Feb 17 23:55:01.549 sat: ISAKMP (0:2): Old State = IKE_QM_I_QM1  New
State = IKE_QM_PHASE2_COMPLETE

Feb 17 23:55:01.653 sat: ISAKMP (0:2): retransmitting phase 1 QM_IDLE
...

Feb 17 23:55:01.653 sat: ISAKMP (0:2): incrementing error counter on sa:
retransmit phase 1

Feb 17 23:55:01.653 sat: ISAKMP (0:2): no outgoing phase 1 packet to
retransmit. QM_IDLE

Feb 17 23:55:08.049 sat: ISAKMP (0:1): purging SA., sa=81B23F90,
delme=81B23F90

Feb 17 23:55:08.049 sat: CryptoEngine0: delete connection 1

Feb 17 23:55:08.049 sat: CryptoEngine0: CRYPTO_ISA_SA_DELETE(hw)(ipsec)

Feb 17 23:55:51.549 sat: ISAKMP (0:2): purging node 567506243

 



=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to