Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

VPN from PIX515 to checkpoint

Posted on 2009-07-10
2
375 Views
Last Modified: 2013-11-16
I have a vpn setup  from PIX515 V7.0 to checkpoint. i am getting phase 1 to complete but phase 2 does not come up.  using aes-256/md5 on both sides. and lifetime is the same. looking for help more on the pix side of my setup to make sure config is correct. i do have a site to site up and running to another location from this pix to another pix.
0
Comment
Question by:Firstcorp
2 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
ID: 24826019
How are you certain phase 1 completes?   Log files?  

If you're sure phase 2 is failing, then look at 1 of these:
1) mismatch or unsupported IPSEC proposals
2)The crypto and nonat access lists don't match on each side.   Each side's config must match exactly. \


If it fails, post a snippet of the log file....
0
 

Author Closing Comment

by:Firstcorp
ID: 31602198
It was the renegatiate time on the checkpoint.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question