This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ASG 220 and Checkpoint FW-1 VPN problem (invalid message id)

Hi all, 
I have tried to establish a VPN between ASG 220 and CheckPoint FW1 NG with AI R55 HFA17 and the curious thing about that, is that the tunnel is working fine in just one direction. I mean, if a begin the conection from the network behind de ASG 220 everything is fine, but if I try to begin the conection from the network behind de Checkpoint i received the Following error message in the Smart View Tracker log system...:
 
Number:                            1282
Date:                                 29Jun2006
Time:                                 15:11:36
Product:                            VPN-1 & FireWall-1
Interface:                           daemon
Origin:                               Checkpoint (YY.YY.YY.YY)
Type:                                 Log
Action:                               Key Install
Source:                             Astaro (XX.XX.XX.XX)
Destination:                      Checkpoint (YY.YY.YY.YY)
Encryption Scheme:         IKE
VPN Peer Gateway:          Astaro (XX.XX.XX.XX)
IKE Phase2 Message ID: 7fe5de51
Information:                      IKE: Quick Mode Received Notification from Peer: invalid id information 


Number:                            1283
Date:                                 29Jun2006
Time:                                 15:11:36
Product:                            VPN-1 & FireWall-1
Interface:                           daemon
Origin:                               Checkpoint (YY.YY.YY.YY)
Type:                                 Log
Action:                               Key Install
Source:                             Astaro (XX.XX.XX.XX)
Destination:                      Checkpoint (YY.YY.YY.YY)
Encryption Scheme:         IKE
VPN Peer Gateway:          Astaro (XX.XX.XX.XX)
IKE Phase2 Message ID: 72ab9253
Information:                      IKE: Quick Mode Received Notification from Peer: invalid message id 

I have triplechecked the configuration parameters on both sides of the tunnel, and everything is exactly the same way in the boxes.
I have been searching on the Secure Knowledge Base in the Checkpoint site , but there is nothing related to that issue. I also tried this forum , but i haven't found anything useful for my problem...
I'll be waiting for those of you who know how to solve this...

Regards...
Radiohead [:O]


This thread was automatically locked due to age.
Parents
  • in the KnowledgeBase, search on: checkpoint

    The documents are written for earlier versions of Astaro, but the Astaro IPsec is still the same.  If you are unsuccessful after making any changes recommended in those documents, please show the lines from the Astaro IPsec log and explain if either the Checkpoint or the Astaro is behind another firewall.

    Cheers - Bob
  • Hi all,

    I have the same problem an I can't find the dokuments in the knowlede base. Could you explane, how you solved this problem?

    Thanks,
    Tini
Reply Children
No Data