Check to see whether Aggressive mode is turned on or off on both sides.  It is recommended to turn it off, if using pre-shared secrets.  The username is passed in the clear using aggressive mode.
-----Original Message-----
From: Hrvoje Dunkic [mailto:[EMAIL PROTECTED]]
Sent: Thursday, October 10, 2002 6:16 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] Site-to-Site VPN

Hi All,

 

We where using IKE Site-to-site VPN using pre-shared secret with our IT solutions partner. Both Windows 2000 Servers with VPN-1 v4.1. Unfortunately I deleted there's firewall workstation object. There was no changes in NAT rule and Security Policy rule.

I manage to reconstruct deleted object with some help from partner's Checkpoint guy. I'm pretty shore that configuration is same as before.

 

When I try to send anything to other site, I get these errors in fw.log:

 

IKE: Aggressive Mode Sent Notification: authentication failed

 

or

 

encryption failure: Encryption/Decryption Failure

encryption failure: Packet is droped as there is no valid SA

 

Does anybody has a clue ?

 

Hrvoje       

 

Reply via email to