Solved

Site-to-Site VPN between ISA 2004 standard and WatchGuard firewall

Posted on 2008-10-20
2
892 Views
Last Modified: 2013-11-16
Hello,

I have created a site to site VPN using PISEC with a preshared key between a ISA server 2004 and a WatchGuard firewall.
When I ping an address behind the WatchGuard firewall I get  "negotiating ip security".

On the ISA 2004 I have

- Created a remote site connection pointing to the outside address of the WatchGuard firewall with a pre-shared key.

- Created two network rules to route from and to WatchGuard firewall

- Created access rules on isa 2004 indicating to and from WatchGuard firewall

When I ping  an address behind the WatchGuard firewall from the isa 2004 I get "negotiating ip security".When I ping from behind the isa server 2004 I get request timed out.
When I look at the monitoring logs I can see both pings being initiated .When I look at site sessions for the remote site I do not get any indicators that the linl is up between both sites.


Isa 2004
Inside address range 192.168.116.0/255.255.255.0
outside address is 100.0.0.100  (mentioned wrong one for security reasons)

WatchGuard Firewall
Inside address range 192.168.1.0/255.255.255.0
outside address is 200.0.0.200  (mentioned wrong one for security reasons)


FYI - Previously there was Cisco PIX firewall which is DOWN now. So trying to replace it with ISA Server.

Please Advise,

Bhvn
0
Comment
Question by:p_bhvn
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 32

Expert Comment

by:dpk_wal
ID: 22760454
Although I would not be much help with ISA configuration; I would be able to assist you with WG configuration; can you post few sanitized logs from watchguard traffic monitor which would help explain the reason the negotiations are failing.

Thank you.
0
 

Accepted Solution

by:
p_bhvn earned 0 total points
ID: 22790421
I upgraded it to ISA 2006 and it worked fine.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

ISA Server detected routes through the network adapter LAN that do not correlate with the network to which this network adapter belongs What does this mean and how can one go about correcting it? In simple terms, this error message indicates t…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question