Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Checkpoint R56 <> PIX VPN

Status
Not open for further replies.

rickrude11

IS-IT--Management
Jul 15, 2007
71
NZ
Hi guys,
I have setup a number of VPNs, to various companies, including some to other PIX devices, but this one has me stumped.

The other end can establish a tunnel by pinging me or whatever, but I can't establish the tunnel at all. There is an error in my log that says "Packet is dropped because there is no valid SA". Once he pings me and the tunnel is established, communication is all go in both directions.

Any 2cents appreciated.

 
It means that the access-lists for interesting traffic don't match on each end.
 
Thanks for the quick response. I will investigate how to specify interesting traffic on the Checkpoint box. As far as I was aware, any traffic destined to the other end is considered interesting.

 
Yes that would be true, and both sides of the tunnel have to have mirrored configuration.
 
Mirrored configuration such as encrytion types etc yes, but are you saying that interesting traffic access-lists have to match?
 
Yes they do, or you will get errors such as unknown security association as you have seen.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top