We are running that exact scenerio with one of our partners.  Check that
both firealls have the exact same encryption settings, also make sure that
you include both the valid and invalid IPs in your encryption domain. You
only need the valid IPs for your partner's network. 

-----Original Message-----
From: Darryl Bowler [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, October 04, 2000 10:22 AM
To: [EMAIL PROTECTED]
Subject: [FW1] VPN + NAT



anyone had luck running a VPN between 2 checkpoint FWs which have NATed lans
with private address ranges behind them ?
Using IKE.

When I  configure NAT (auto hide) I get the following errors
icmp-type 0 icmp-code 0 encryption failure: Packet is not IPSEC scheme: IKE

Without NAT, it works fine.


Regards Darryl



============================================================================
====
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
============================================================================
====


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to