[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

10/24/2009 at 06:05PM PDT, ID: 24841183 | Points: 500
[x]
Attachment Details

VPN Tunnel "No Proposal Chosen" error

Asked by boblzer0 in Virtual Private Networking (VPN), Watchguard Firewall, IPSec Security Protocol

Tags: vpn, firebox, ipsec

Just upgraded a firebox x700 from WSF7.5 to WSM9 with Fireware.  VPN tunnels (ipsec) that previously worked before the upgrade are now not connecting.  

Network is setup in Hub/Spoke design.  The hub is 192.168.1.0/24 and is a Watchguard Firebox X700 running Fireware 9.0.  The first spoke that I am having issue with is a SonicWall TZ 170 at 192.168.8.0/21.  This VPN tunnel worked before we upgraded the firmware on the Hub device.   I am apparently missing something in re-inputting the config that is preventing it from working.  Please see code below for error from log.  All settings are matched up to what they were before the firmware upgrade.  Any ideas of what I'm missing?
1:
2:
3:
2009-10-24 20:59:14 Deny 192.168.1.222 192.168.10.15 icmp-Echo 1-Trusted Intercare/IPsec  SA deleted or negotiation failed, firewall drop  (Ping-00)  
2009-10-24 20:59:14 iked Starting phase 2 to 173.10.41.108:500 quick mode message(id f998a557)  
2009-10-24 20:59:14 iked The Firebox received this error (No Proposal Chosen) from 173.10.41.108:500
[+][-]10/25/09 09:30 AM, ID: 25657124

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/25/09 12:58 PM, ID: 25657971

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/29/09 07:09 PM, ID: 25699773

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20090824-EE-VQP-74 - Hierarchy / EE_QW_3_20080625