JuniperForum.com
September 09, 2010, 02:36:36 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Checkpoint-Netscreen VPN  (Read 1815 times)
netmanau
Newbie
*
Posts: 6


View Profile
« on: March 02, 2003, 09:40:08 PM »

Hello

I'm trying to setup a LAN-to-LAN VPN between a Checkpoint NG and a Netscreen 100 3.0.3r3 using Preshare/DES/MD5. I am having trouble with Phase 2 negotiations:

Multiple SA for multiple policy mode, skipping base sa 11 when searching for sa.
##2003-03-03 10:53:00 system-debugging: IKE <y.y.y.y> Phase 2: No policy exists for the proxy ID received: local ID(x.x.x.x>/<255.255.254.0>,<0>,<0>) remote ID (<y.y.y.y>/<255.255.255.255>,<0>,<0>)

y=Host on trusted side of Checkpoint, x=Trusted Netscreen Address Range

The Netscreen knowledgebase suggests this is because I do not have the correct incoming policy, but I have made sure this is not the case. Any other ideas what could be causing this?
Thanks
Logged
cyh
Full Member
***
Posts: 117


View Profile
« Reply #1 on: March 03, 2003, 01:15:02 AM »

check you address as well.
you should set the two addresses like:

set address t1 trust x.x.x.x 255.255.254.0
set address u1 untrust y.y.y.y 255.255.255.255

and the policy should be like

set policy incoming u1 t1 any tunnel vpn vpn1

Or use WebUI.
Logged
netmanau
Newbie
*
Posts: 6


View Profile
« Reply #2 on: March 04, 2003, 05:36:02 PM »

Addresses are fine too. I've even tried changing the policy to allow all untrusted ip addresses though but still get this error.
Logged
netmanau
Newbie
*
Posts: 6


View Profile
« Reply #3 on: March 04, 2003, 10:07:01 PM »

Also there are NATs on the checkpoint which translate to public addresses. Both internal and NATed public addresses have been added to the incoming policy.

A 'get sa' command shows the tunnel as active and I can ping hosts on trusted side of Checkpoint from trusted side of Netscreen, however when I ping from the Checkpoint side the error occurs in Netscreen logs. Does NATing at the Checkpoint affect the proxy id (other than ip address) to make it unrecognisable to the Netscreen?
Logged
Florent
Hero Member
*****
Posts: 1089


View Profile WWW
« Reply #4 on: March 05, 2003, 08:34:19 AM »

what is the exact source IP, destination IP and services defined in both Netscreen and Checkpoint ?
Logged

FlO
__ www.netsc.ch __
Florent
Hero Member
*****
Posts: 1089


View Profile WWW
« Reply #5 on: March 06, 2003, 11:18:55 AM »

I encoutered the same problem.
It looks like the DOI on checkpoint is strange and come from space Wink
which NG version are you running ?

If you need to have this quickly working, unset ike pol on NS solve the problem (just to wait)
Logged

FlO
__ www.netsc.ch __
netmanau
Newbie
*
Posts: 6


View Profile
« Reply #6 on: March 06, 2003, 04:55:47 PM »

Thanks for that Flo. The problem was that the incoming policy on the Netscreen would not allow me to use groups of addresses!! It would only work when I specified individual addresses which corresponded exactly to the outgoing on the Checkpoint. I got around this by using a subnet mask on an individual address (luckily all the addresses i wanted to allow in were sequential and inside one small network!)
Logged
Florent
Hero Member
*****
Posts: 1089


View Profile WWW
« Reply #7 on: March 07, 2003, 01:58:29 AM »

Quote from: netmanau
The problem was that the incoming policy on the Netscreen would not allow me to use groups of addresses!!


This is the same with a majority of other VPN device since Netscreen use the IP 0.0.0.0 when a group is used (and 0 for a service group) and lot of others will negociate IKE for each member of an IP group individualy.

Quote from: netmanau

It would only work when I specified individual addresses which corresponded exactly to the outgoing on the Checkpoint.


Another time, the proxy id must always exactly match with peer gateway.

Quote from: netmanau

I got around this by using a subnet mask on an individual address (luckily all the addresses i wanted to allow in were sequential and inside one small network!)


There is another thing to ntoe with NG. There is some behavior that change during IKE negociation between 4.1 and NG. A working VPN config with 4.1 is not working in one direction after NG upgrade.

if someone here has checkpoint skills, he can help to understand the change.
Logged

FlO
__ www.netsc.ch __
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 40719
  • Total Topics: 11389
  • Online Today: 82
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 0
Guests: 48
Total: 48
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.226 seconds with 37 queries.