Dear Firewall Lads,
 I have a strange-horrible-desperate problem: I've two VPNs, one from London
to Miami, anotherone from London to Costa Rica. Yesterday, the VPN from
London to Costa Rica stoped working (had to change the evaluation licence).
However, the Miami-London is great after the change.
 I checked the encryption options on the firewall objects, changed the
encryption schemes,  checked the properties of the action "encrypt" on the
rule base, checked the System Status, checked the encryption domains, tried
changing the agressive mode. I can install policies on both modules, the
system status says everything's ok. It is exactly configure like the
miami-london VPN.

In the Log viewer I get these errors concerning this VPN after several test
runs:
-"encryption failure: cannot calculate IKE ranges"
-"encryption failure: no response form peer"
-"encryption failure: Encryption/Decryption Failure"

...and the one that terrifies me:

-"encryption failure: Packet is dropped as there is no valid SA"

I did my research on the list archives and found someone with the same
problem: the same error, he also upgraded to NG from 4.1, and couldn't set
the VPN. I hope this person solved his problem and is still on the mailing
list so he can help me...

Thanks for your time lads... The only thing that i haven't tested is a
change of licence!!.

Cheers.


LB

P.S.> Is it possible that an Eval licence is corrupted. I mean, even though
I can compile/install policies on both modules and the system status says it
is ok, the VPN doesn't work.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to