Turn off IKE property "Supports key exchange for subnets" and install the
policy.


From: "J. Ruff" <[EMAIL PROTECTED]>
Reply-To: Mailing list for discussion of Firewall-1
<[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [FW-1] IKE Phase2 wrong subnet mask
Date: Mon, 12 Apr 2004 10:33:05 -0400

I've got a L2L vpn that's been functioning just fine for quite some time
now.  All of a sudden, some of the networks at the remote site are not
accessible.  The error received in tracker is:

IKE: Quick Mode Received Notification from Peer: invalid id information

I've verified encryption domains on both ends.  There have been no changes
what so ever on either end.  After running 'vpn debug ikeon' I can see in
vpn.elg that "create_packet1phase2" information has the incorrect subnet
mask specified in the "debugIDPayload" section for the destination
network.  It should be a /24 but instead is a /23.  I checked the network
objects and it is specified as /24.

Here's an overview of what's working and not.
Remote Encryption Domain:
     X.X.215.0/24     - Working
     X.X.216.0/24     - Not Working
     X.X.217.0/24     - Not Working

When communication is attempted to the 216 & 217 nets is specifies the
netmask as /23 in packet #1 of the IKE Phase2 negotiation.

Any ideas???

Thanks.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

_________________________________________________________________ Limited-time offer: Fast, reliable MSN 9 Dial-up Internet access FREE for 2 months! http://join.msn.com/?page=dept/dialup&pgmarket=en-us&ST=1/go/onm00200361ave/direct/01/

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to