Hey,

I have an AI R55 Cluster with a couple of Edge devices connected to it in site-to-site 
VPNs. All of the normal traffic for both devices seem to be working properly, however 
the tunnel tests for one of the Edges is coming in unencrypted, and of the firewall is 
dropping it (stealth rule) . The other Edge's tunnel tests are coming in just fine and 
encrypted. I added a rule to the rulebase to attempt to force this traffic into a VPN 
tunnel, but then i dont just get a drop on the stealth rule but a more detailed error: 
encryption failure: Different community ID, possible NAT problem (VPN Error code 02).  
I understand that I may have to turn off FW-1 connections in the Global Properties, 
and create implicit rules for my control connections, but why would one Edge send in 
the tests encrypted, and the other unencrypted?

Anyone have a clue?
Stewart

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to