Ok-- how?  According to the CP Knowledgebase it isn't possible.

>From article sk14238:

Note:
In order to configure an IKE site to site VPN using pre-shared secrets for
VPN-1 / FireWall-1 NG FP2, it is necessary to configure the rulebase using
the Traditional Mode since configuring an IKE site to site VPN using
pre-shared secrets for VPN-1 / FireWall-1 NG FP2 is not supported for
Simplified Mode

>From article sk18888:

Site to site VPN Communities using pre-shared secret are not supported for
the following:

VPN-1 / FireWall-1 NG FP2
VPN-1 / FireWall-1 NG FP1

In order to set up site to site VPNs using pre-shared secrets for VPN-1 /
FireWall-1 NG FP1 and VPN-1 FireWall-1 NG FP2, configure the Rule Base using
Traditional Mode as the VPN configuration method.

I'm willing to believe there's another way, but "no, that's wrong, yes it
can" doesn't tell me how :)

Thx,
---
Russell Washington, CCSE, CCSA, NCSA
Too many doggoned letters after my name.../

----- Original Message -----
From: "Michael Haffely" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, January 09, 2003 2:04 PM
Subject: Re: [FW-1] Simplified mode to Trad mode VPN?


It can be done with shared secrets.

>>> [EMAIL PROTECTED] 1/9/2003 2:12:58 PM >>>
Tweaks/clarifications to this Q:

- Specifically, is it possible to do this using preshared secrets.  I'm
betting the answer is no.

- If it can't be done using preshared secrets, can this be set up using
certificates provided by the ICA to both sides, or do you have to go with
real-world purchases from Verisign/Thawte/etc., for each side;

- With all this brouhaha in mind, how on earth does an NG CP with a
simplified rulebase do a site-to-site VPN with a *non*-Check Point, yet
still IPSec-compliant, VPN device?

Thx,
---
Russell Washington, CCSE, CCSA, NCSA
Too many doggoned letters after my name.../


----- Original Message -----
From: "Russell Washington" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, January 09, 2003 10:54 AM
Subject: [FW-1] Simplified mode to Trad mode VPN?


One of my clients is using an NG-based Traditional rulebase and has to deal
with a number of other-platform VPNs.  So far so good until one of their
clients turned up NG with a simplified-mode rulebase.  Their client doesn't
know how to get the simplified rulebase to talk to a traditional mode NG
peer.

Of course, they didn't cover this scenario in training-- everyone is
*supposed* to use simplified mode right?  Yeah yeah yeah.  :)

Has anyone done this before and can you lend some insight?  The
traditional-mode end is easy, it's the simplified end we can't figure out,
since it *is* talking to another Check Point, but that Check Point obviously
isn't "working the way it expects" and hence the confusion.

Thx for any help...
---
Russell Washington, CCSE, CCSA, NCSA
Too many doggoned letters after my name.../

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================



**********************************************************************
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the system manager.
**********************************************************************

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to