Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

CHeckpoint 4.1 firewall and Cisco Pix v6.2(2) VPN setup

Status
Not open for further replies.

lengoo

IS-IT--Management
Jan 15, 2002
381
GH
Hi All,
I am having problems setting up a VPN between our CHeckpoint 4.1 firewall and another company Cisco Pix. I have actually done this before but this time round, we're not so lucky, it's not working!
I am actually get Phase 2 which means the tunnel is up and running.. however, when the remote end try to get into our network, they get an error message...

“encryption failure: error occurred scheme: IKE”

and the packet is dropped.

It's almost like even though the tunnel is up, the packets aren't being encrypted.

I have 2 rulesets which should do this though,

Source Destination Service Action
internal external any encrypt
external internal any encrypt

I have configured this to work with IKE running DES as the algorithm, MD5 as the integrity check and ESP as the transform, pre-shared secret key

Has anyone have any ideas as to what could be wrong here???

Mucho gracias
 
Check your security Association values. Cisco router's default security association is different from that of checkpoint and both values must be the same either in seconds or minutes for phase 2 to work.

Thanks.
Isokocons
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top