[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [FW-1] No SR VPN after upgrade to IPSO 3.6-FCS6 & NG FP3 HF1 HFA_305
Hi
all,
I am
wondering if someone has encountered following situation during his
migration,
and of course I'd
like to know too how it has been fixed.
The
environment is :
-
Management = Windows Nt 4.0-SP6a + CheckPoint NG FP3 + HF1 +
HFA_305
-
Firewall = Nokia IP440 IPSO
3.6-FCS6 + CheckPoint NG FP3 + HF1 + HFA_305
--> this
one was coming from 4.1-SP3 ... then NG FP1
Due to
several other issues we had before, we delayed this upgrade till
now.
The
Firewall is in fact an HA solution, using VRRP MC, on which we broke the
cluster, one
module is still up
and running with 4.1 and the second member has been migrated to
the
above mentioned
version.
Since then, when trying to establish
a SR VPN with the module we get following error message:
dst scheme NA:
route status temporary unavailable resources.
The
rule showing this error is the one that should encrypt my SR connections, I can
authenticate,
but the rule rejects
the connection, and it is in the clear, not encrypted !!
I
read article sk16981 in the Check Point knowledge base but they ask to install
HFA_303, but
I installed a higher
version HFA_305 !!!
If nobody has seen this before I think I'll have to downgrade once more and
start upgrading
step by step and
after each step test !!
Thank
you for any ideas you might have.
Met vriendelijke groeten - Bien à vous -
Kind regards
|