Edit user.def on management and add a section similar to the following:
#define __user_def__
max_subnet_for_range = {
<x.x.216.0, x.x.217.255; 255.255.255.255>
};
This will present all hosts between x.x.216.0 and x.x.217.255 as individual
hosts without any summarization. You can modify the mask to reflect the
largest subnet you want to present within the range.
Save and push policy.
-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] Behalf Of J. Ruff
Sent: Monday, April 12, 2004 2:57 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] IKE Phase2 wrong subnet mask
Thanks all.
The field value change makes the most sense in this scenario because after
removing the one X.X.217.0/24 from the dest encrypt-domain the
X.X.216.0/24 net was masked properly in the IKE Phase2 packet.
So I used dbedit and issued the following command(sorry for line wrap):
dbedit> modify properties firewall_properties
ike_use_largest_possible_subnets flase
I then installed policy, but the problem still exist. I verified the
value of ike_use_largest_possible_subnets had changed (and it did) from
'true' to 'false'. The IKE Phase2 packet is still addressing both the
X.X.216.0/24 & X.X.217.0/24 as one /23 net.
Any ideas on what should be done now???
Thanks in advance.
> Rays suggestion should solve the problem, but may also result in
> excessive SA negotiations (depending on your traffic)
> I would suggest that you give "ike_use_largest_possible_subnets" a try.
> You can change the value from true to false via
> dbedit or guidbedit install the policy ...
>
> Regards
> Ulli
>
> On Apr 12, 2004, at 4:33 PM, J. Ruff wrote:
>
>> I've got a L2L vpn that's been functioning just fine for quite some
>> time
>> now. All of a sudden, some of the networks at the remote site are not
>> accessible. The error received in tracker is:
>>
>> IKE: Quick Mode Received Notification from Peer: invalid id information
>>
>> I've verified encryption domains on both ends. There have been no
>> changes
>> what so ever on either end. After running 'vpn debug ikeon' I can see
>> in
>> vpn.elg that "create_packet1phase2" information has the incorrect
>> subnet
>> mask specified in the "debugIDPayload" section for the destination
>> network. It should be a /24 but instead is a /23. I checked the
>> network
>> objects and it is specified as /24.
>>
>> Here's an overview of what's working and not.
>> Remote Encryption Domain:
>> X.X.215.0/24 - Working
>> X.X.216.0/24 - Not Working
>> X.X.217.0/24 - Not Working
>>
>> When communication is attempted to the 216 & 217 nets is specifies the
>> netmask as /23 in packet #1 of the IKE Phase2 negotiation.
>>
>> Any ideas???
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
***********************************************************************
This electronic transmission contains information from Methodist Health
System and should be considered confidential and privileged. The
information contained in the above messages is intended only for the
use of the individual(s) and entity(ies) named above. If you are not
the intended recipient, be aware that any disclosure, copying,
distribution, or use of this information is prohibited. If you receive
this transmission in error, please notify the sender immediately by
return e-mail. Methodist Health System, its subsidiaries and
affiliates hereby claim all applicable privileges related to the
transmission of this communication.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================