NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] VPN between FW-1 4.0 and a Gnatbox



Means that the encryption properties for the ike session between the fw-1
box and gnat are not exactly the same.

----- Original Message -----
From: "Petra Klein" <[email protected]>
To: <[email protected]>
Sent: Wednesday, December 19, 2001 7:17 AM
Subject: [FW-1] VPN between FW-1 4.0 and a Gnatbox


> Hi,
>
> I'm trying to set up a VPN between a Firewall-1 4.0 SP-3 and a Gnatbox.
> We are both using the same settings. ISAKMP(IKE) Mainmode/DES/SHA-1/PFS.
>
> The Firewall-logs:
> "IKE Log Sent Nofification: no proposal chosen <Phase1 Stage1>"
>
> The Gnatbox logs:
> error -> isakmp_inf.c:797:isakmp_info_recv_n(): notification message
> 14:NO-PROPOSAL-CHOSEN
>
>
> A tcpdump will show:
>
> 15:47:01.330071 x.x.x.1.500 > x.x.x.2.500:
> isakmp: phase 1 I ident:
>     (sa: doi=ipsec situation=identity
>         (p: #1 protoid=isakmp transform=1
>             (t: #1 id=ike (type=lifetype value=sec)(type=lifeduration
> value=1518)(type=lifetype value=kb)(type=lifeduration len=4
> value=0001e000)(type=enc value=1des)(type=auth value=preshared)(type=hash
> value=sha1)(type=group desc value=modp1024))))
>
> 15:47:01.357485 x.x.x.2.500 > x.x.x.1500:
> isakmp: phase 2/others R inf:
>     (n: doi=ipsec proto=isakmp type=NO-PROPOSAL-CHOSEN)
>
> Any suggestions?
> Help is appreciated!
>
> Sincerely
> Petra
>
> =================================================
> To set vacation, Out Of Office, or away messages,
> send an email to [email protected]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [email protected]
> =================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.