Solved

Site-to-Site VPN between ISA 2004 standard and WatchGuard firewall

Posted on 2008-10-20
2
840 Views
Last Modified: 2013-11-16
Hello,

I have created a site to site VPN using PISEC with a preshared key between a ISA server 2004 and a WatchGuard firewall.
When I ping an address behind the WatchGuard firewall I get  "negotiating ip security".

On the ISA 2004 I have

- Created a remote site connection pointing to the outside address of the WatchGuard firewall with a pre-shared key.

- Created two network rules to route from and to WatchGuard firewall

- Created access rules on isa 2004 indicating to and from WatchGuard firewall

When I ping  an address behind the WatchGuard firewall from the isa 2004 I get "negotiating ip security".When I ping from behind the isa server 2004 I get request timed out.
When I look at the monitoring logs I can see both pings being initiated .When I look at site sessions for the remote site I do not get any indicators that the linl is up between both sites.


Isa 2004
Inside address range 192.168.116.0/255.255.255.0
outside address is 100.0.0.100  (mentioned wrong one for security reasons)

WatchGuard Firewall
Inside address range 192.168.1.0/255.255.255.0
outside address is 200.0.0.200  (mentioned wrong one for security reasons)


FYI - Previously there was Cisco PIX firewall which is DOWN now. So trying to replace it with ISA Server.

Please Advise,

Bhvn
0
Comment
Question by:p_bhvn
2 Comments
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
Although I would not be much help with ISA configuration; I would be able to assist you with WG configuration; can you post few sanitized logs from watchguard traffic monitor which would help explain the reason the negotiations are failing.

Thank you.
0
 

Accepted Solution

by:
p_bhvn earned 0 total points
Comment Utility
I upgraded it to ISA 2006 and it worked fine.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Microsoft's ISA Server has been its pre-eminent security product for about a decade and is still regarded amongst the well-informed as one of the best software firewalls and application gateways ever released, by any manufacturer. ISA Server has bee…
So the following errors occurs in 2 ways that I am aware of at this stage, and you receive one of the following error messages: ERROR 1. When trying to save a rule: No Web listener is specified for the Web publishing rule Autodiscovery Publishin…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now