Hi, We're getting now "Local Interface Address Spoofing" message_info. this normal occurs just before an IKE key exchange renewal. This is occuring more frequently, at least once in the morning and once in the afternoon. When this happens, our site-to-site links (one to a Cisco PIX (an ISP) and the other to an OpenSwan running on Debian - it's an ISP) does not work. So, I have to do a cpstop/cpstart to force the links to do a key exchange. A policy push/install does not resolve the issue. Normally, the vpn to the Cisco PIX comes again immediately after doing the cpstop/cpstart whereas the link the OpenSwan takes awhile to work back again. >From the ISP running the openswan, their logs show that our fw1 is trying to communicate using the address of the internal interface instead of the address of the external interface. We could get the logs from the ISP running the Cisco PIX. >From the ISP operating the Cisco PIX, they're claiming that our external address is not configured for the crypto. Unfortunately, this is the most important site as many of our staff rdp's to the hosted VM's there. This issue started happening after we change the address of the internal interface of our fw1. The vpn links are configured to communicate to the external interface of FW1. We're still running R55 NGAI HFA20 (we're going to upgrade to R75 blades hopefully soon rather than later). We have lots of VLAN's behind the internal interface that connects to the hosted VM's. So far, all routing are working correctly (unless I've missed something). The key to the resolution of the issue is to resolve the "Local Interface Address Spoofing" error. I've searched the Net, CP KnowledgeBase, etc. The solutions put forward such as disabling the Anti-spoofing ,etc, does not work. Any ideas for the resolution of the problem is greatly appreciated. ta czar
================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
