There are many things that will cause this errors.
 
        Check both FW objects, especially the authenaication methods, such as MD5, SHA ..... Since the errors show "

IKE: Aggressive Mode Sent Notification: authentication failed", So I guess it might be caused by the mis-configuration causing Phase 1 failed to negotiate.

 

        Also check the policy again, make sure that both side's network objects are same.

 

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED]]On Behalf Of <Aaron Reynolds>
Sent: Friday, October 11, 2002 1:20 AM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Site-to-Site VPN

Check to see whether Aggressive mode is turned on or off on both sides.  It is recommended to turn it off, if using pre-shared secrets.  The username is passed in the clear using aggressive mode.
-----Original Message-----
From: Hrvoje Dunkic [mailto:[EMAIL PROTECTED]]
Sent: Thursday, October 10, 2002 6:16 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] Site-to-Site VPN

Hi All,

 

We where using IKE Site-to-site VPN using pre-shared secret with our IT solutions partner. Both Windows 2000 Servers with VPN-1 v4.1. Unfortunately I deleted there's firewall workstation object. There was no changes in NAT rule and Security Policy rule.

I manage to reconstruct deleted object with some help from partner's Checkpoint guy. I'm pretty shore that configuration is same as before.

 

When I try to send anything to other site, I get these errors in fw.log:

 

IKE: Aggressive Mode Sent Notification: authentication failed

 

or

 

encryption failure: Encryption/Decryption Failure

encryption failure: Packet is droped as there is no valid SA

 

Does anybody has a clue ?

 

Hrvoje       

 

Reply via email to