Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Checkpoint NG to 4.1 VPN - Decrypted Methods didn't matched rule

Status
Not open for further replies.

Gavw12

MIS
Jul 24, 2002
8
0
0
DE
Hi

I have a Multi-Site VPN with various versions of Checkpoint FW-1 that all connect to a central "DataCentre" that uses 4.1 SP5 on NT4. One of the newer sites is using NG FP2, and successfully tunnels to the DataCentre using DES, MD5, No Compression, PFS, DH Group2. Anywhere from 1 to 4 times a day, just after IKE Main Mode / Quick Mode negotiation the tunnel breaks down and the log shows the following;

encryption failure: Decrypted Methods didn't matched rule

If left alone, it resolves itself in anything from a few minutes to as long as an hour. I have tried recreating the encryption rules from scratch, chosen a different shared key. Has anyone seen this error or have any idea where I'm going wrong?

Thanks

Gavin
 
I have had similar issues in the past not exactly the same but to solve the problem make sure that you only have 3des checked and no others checked. Obviously if you not runnung 3des then whatever encryption scheme you using.

This seems trivial but it solved my problem.

 
Hi Freeb26,

Thanks for replying, unfortunately I had already configured the NG box this way. I can't find references to this error message anywhere... :(
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top