I've seen this before on our firewall when I was being lazy and tried doing
this with one rule:

--------------------------------------------------
domain_1        domain_2        ANY             ENC     LONG
domain_2        domain_1        
--------------------------------------------------

but when you change it to:

--------------------------------------------------
domain_1        domain_2        ANY             ENC     LONG
--------------------------------------------------
domain_2        domain_1        ANY             ENC     LONG
--------------------------------------------------

It seemed to go away.  Do you have any overlaping domains?


> -----Original Message-----
> From: Emili Badia [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, September 05, 2000 1:07 PM
> To: [EMAIL PROTECTED]
> Subject: [FW1] gateway connected to both endpoints scheme
> 
> 
> 
> We have a VPN configuration that fails to encrpyt communications.
> 
> Log file shows next message:
> 
> encryption failure: gateway connected to both endpoints scheme: FWZ
> 
> the rules we have are:
> 
> Sourc     Destination      Service     Action     Track
> domain_1    domain_2    Any        Encrypt     Long
> domain_2    domain_1    Any         Encrypt    Long
> 
> In the firewall we have in the first domain, when we 
> configure encription
> domain we just add an object that includes the domain_1 and domain_2.
> The same in the second firewall.
> Any idea?
> 
> 
> 
> 
> ==============================================================
> ==================
>      To unsubscribe from this mailing list, please see the 
> instructions at
>                http://www.checkpoint.com/services/mailing.html
> ==============================================================
> ==================
> 


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to