Is your VPN Domain setup correctly? If so, do a "vpn debug" command on the firewall while performing the ping.
-----Original Message----- From: LAN Guy [mailto:[EMAIL PROTECTED] Sent: Tuesday, March 15, 2005 10:57 AM To: [email protected] Subject: [FW-1] NG to Cisco 3000 VPN Problem I'm setting up an IPSEC VPN between my NG-AI R54 gateway and a partner's Cisco VPN 3000 Concentrator. Everything looks like it's set up properly (same IKE parameters, shared secret, etc), but every time I try to ping from my net to the partner net over the tunnel it fails with the same 3 log entries: ------------- #1 Action: Key Install Source: [my gateway] Destination: [partner gateweay] Encryption Scheme: IKE VPN Peer Gateway: [partner gateweay] IKE Initiator Cookie: 54b2334ee5635973 IKE Responder Cookie: baa23cf0ae5b945d Encryption Methods: 3DES + MD5, Pre shared secrets Community: [vpn community for this partner] Information: IKE: Main Mode completion. ------------ #2 Action: Key Install Source: [my gateway] Destination: [partner gateweay] Encryption Scheme: IKE VPN Peer Gateway: [partner gateway] IKE Phase2 Message ID: 06094fba Community: [vpn community for this partner] Information: IKE: Quick Mode Sent Notification: invalid id information ------------ #3 Action: Key Install Source: [partner gateway] Destination: [my gateway] Encryption Scheme: IKE VPN Peer Gateway: [partner gateway] IKE Phase2 Message ID: 31604fab Community: [vpn community for this partner] Exchange Received Delete IPSEC-SA from Peer: 0c69e9ed SPIs: 61e6bdf7 Then the traffic fails because there is no valid SA. Has anyone had some similar experience with this type of setup and knows the particulars?? All help appreciated. Frank P. _________________________________________________________________ FREE pop-up blocking with the new MSN Toolbar - get it now! http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/ ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] ================================================= ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
