Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

VPN/IKE Problem with return packets

Status
Not open for further replies.

thorfun

IS-IT--Management
Jun 25, 2001
7
0
0
GB
Hello all,

I am having a very bizarre problem and have pulled all my hair out over this and am now seeking the infinite wisdom of the net! the problem is as follows (and i'm afraid that it does get a little complicated!):

i am establishing a VPN with another site. They are pinging a server in our office and i can see the packets in the log coming in via the tunnel and the icmp packet is being decrypted by our firewall and the destination address is being translated to the correct internal IP address. if i snoop the interface of the server i can see the packets hitting the server and a reply being sent back to the firewall. if i snoop the internal interface of the firewall i can see the icmp requests and replies going back and forth to the target server but the reply packets are not going back through the vpn tunnel and are just being sent unencrypted via the internet. The firewall log is also showing that the reply packets for some reason are coming from the external IP address of the server in our office and are then getting translated to the internal IP address (which i don't understand) but a snoop of the external interface of the firewall shows that they are going back over the internet with the correct external IP address!

All of the above is being done using the automatic translation rules. if i setup a second object and do manual translation rules the return packet is not going via the internet (horray!) but they are getting dropped in the firewall at the correct rule number where it is stated that it should encrypt packets and the only error message in the log that i'm getting is as follows:

"icmp-type 0 icmp-code 0 encryption failure: error occured scheme: IKE"

so....2 things i can't understand.

1) why when doing automatic NAT are the return packets not being sent through the VPN tunnel?

2) why are the manually NAT'd packets getting dropped with the above error and what does that error mean?

if anyone can help with this it will be extremely appreciated.

thanks in advance,

tom.
 
...in addition to this it may help to let you know that if i initiate the ping then i can see the packet from our side of the vpn getting encrypted correctly and being sent down the vpn.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top