I'm setting up an IPSEC VPN between my NG-AI R54 gateway and a partner's
Cisco VPN 3000 Concentrator.  Everything looks like it's set up properly
(same IKE parameters, shared secret, etc), but every time I try to ping from
my net to the partner net over the tunnel it fails with the same 3 log
entries:

-------------
#1

Action:                                 Key Install
Source:                                 [my gateway]
Destination:                    [partner gateweay]
Encryption Scheme:      IKE
VPN Peer Gateway:       [partner gateweay]
IKE Initiator Cookie:           54b2334ee5635973
IKE Responder Cookie:   baa23cf0ae5b945d
Encryption Methods:     3DES + MD5, Pre shared secrets
Community:                      [vpn community for this partner]
Information:                    IKE: Main Mode completion.

------------
#2

Action:                                 Key Install
Source:                                 [my gateway]
Destination:                            [partner gateweay]
Encryption Scheme:              IKE
VPN Peer Gateway:               [partner gateway]
IKE Phase2 Message ID:  06094fba
Community:                      [vpn community for this partner]
Information:                            IKE: Quick Mode Sent Notification: 
invalid
id information

------------
#3

Action:                                 Key Install
Source:                                 [partner gateway]
Destination:                            [my gateway]
Encryption Scheme:              IKE
VPN Peer Gateway:               [partner gateway]
IKE Phase2 Message ID:  31604fab
Community:                      [vpn community for this partner]
Exchange Received Delete IPSEC-SA from Peer: 0c69e9ed
                                               SPIs: 61e6bdf7

Then the traffic fails because there is no valid SA.

Has anyone had some similar experience with this type of setup and knows the
particulars??
All help appreciated.

Frank P.

_________________________________________________________________
FREE pop-up blocking with the new MSN Toolbar � get it now!
http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to