I really don't have much experience with FW-1 but do have oodles of
knowledge in the area of VPN's. Keep in mind that there is a definite
overhead associated with doing a DH exchange at each rekey interval. If the
data requires such security it is an appropriate price to pay, but if it
does not, it could be quite excessive.


----- Original Message -----
From: "Dragomirescu, Radu" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, June 10, 2003 6:47 AM
Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem


> Hi Aaaron,
>
> correct, I'm using PFS. I also tried not to use that, but it didn't work.
> Then I set the PFS to DH-1 and a miracle happens.
>
> Radu
>
> -----Original Message-----
> From: Aaron Brasslett [mailto:[EMAIL PROTECTED]
> Sent: Dienstag, 10. Juni 2003 14:07
> To: [EMAIL PROTECTED]
> Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem
>
>
> Radu,
>
> Are you using Perfect Forward Secrecy?  I thought that DH-2 was necessary
> for PFS in 4.1.
>
> Aaron
>
> -----Original Message-----
> From: Dragomirescu, Radu [mailto:[EMAIL PROTECTED]
> Sent: Tuesday, June 10, 2003 1:53 AM
> To: [EMAIL PROTECTED]
> Subject: Re: [FW-1] NG to 4.1 Site-to-site VPN Problem
>
>
> Hi Aaron,
>
> I had the same problem and  solved that by choosing DH-1 for IKE Phase 2.
> Some guys suggested me not to  use anyone... That solved not really the
> matter, because from time to time I'm loosing the VPN, so I have to reboot
> the firewall running on 4.1 for establishing the tunnel.
>
> Best regards,
> Radu
>
>
> -----Original Message-----
> From: Aaron Brasslett [mailto:[EMAIL PROTECTED]
> Sent: Montag, 09. Juni 2003 20:50
> To: [EMAIL PROTECTED]
> Subject: [FW-1] NG to 4.1 Site-to-site VPN Problem
>
>
> Hi all,
>
> I have a site to site VPN between a Checkpoint 4.1 SP6 firewall on NT4.0
> SP6a and a Nokia IP120 Running Checkpoint NG FP3 IPSO 3.6-FCS3.  At
> seemingly random times the tunnel between the subnets behind these two
> firewalls become inaccessible to each other.  Logs on the 4.1 firewall
don't
> indicate a problem.  The NG logs give the entry "Decrypted methods didn't
> match rule".  Eventually the tunnel will reestablish itself and carry on
as
> nothing has happened... usually within an hour.  I can force the tunnel
back
> up by issuing a CPRESTART on the NG firewall.  I can also force the tunnel
> down by installing the policy on the 4.1 firewall.
>
> I've search thru the archives and have found a few references to this
> problem and a couple of suggestions... No suggestions have worked.
>
> Any ideas?
>
> Thanks.
>
> Aaron
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
>

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to