Hi


I'm trying to initiate a VPN tunnel with Cisco VPN 3000 concentrator.



I disabled the "key exchange for subnets" and made sure that our both
encryption domains are the same.



The IKE phase 1 is OK but we have a problem with phase II.



Below are lines from the log server:



Number:                                    1797300

Date:                                        6May2004

Time:                                        19:15:17

Product:                                    VPN-1 & FireWall-1

Interface:                                   daemon

Origin:

Type:                                        Log

Action:                                      Key Install

Source:

Destination:

Encryption Scheme:       IKE

VPN Peer Gateway:

IKE Initiator Cookie:      0b1c8894899d0183

IKE Responder Cookie:  fa7d955d594d95cd

Encryption Methods:      3DES + MD5, Pre shared secrets

Information:                  IKE: Main Mode completion.



Number:                                    1797301

Date:                                        6May2004

Time:                                        19:15:17

Product:                                    VPN-1 & FireWall-1

Interface:                                   daemon

Origin:

Type:                                        Alert

Action:                                      Key Install

Source:

Destination:

Encryption Scheme:                   IKE

VPN Peer Gateway:

IKE Phase2 Message ID:            fa02713a

Information:                               IKE: Quick Mode Sent
Notification: no subnet support in ike negotiations



Does someone have any suggestions?





Michael Polevoy

eServices system

Desk +972-3-5399250

Mobile +972-54-497012

Mercury Interactive Corporation

Optimizing Bussiness Processes to Maximize Bussiness Results







________________________________________________________________________
This email has been scanned for all viruses.

Mercury Interactive Corporation
Optimizing Business Processes to Maximize Business Results

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to