Home         Log in

Posts Tagged ‘checkpoint’

VPN Phase 1 fails - Checkpoint to Cisco

May 12th, 2008 by devnull | No Comments | Filed in Uncategorized, firewalls

I recently encountered a problem setting up a VPN tunnel between a Cisco router and a Checkpoint firewall.

From the firewall side, i could see an IKE packet going out, and nothing coming back. 

On the Router side, there was a reply to the IKE, but an error logged:

“Duplicate Phase 1 packet detected.  Retransmitting lastpacket.”

Now this error should appear if the reply is discarded on the firewall side, and it tries to re-send the initial IKE packet. 

Nothing indicated it in the firewall log. 

What solved it was enabling Aggressive Mode on the firewall side. 

I didnt have the time to go over and see why this helped, but it did the trick, so i moved on. 

Another thing, and this is more of a reminder for me, the command for tunnel handling on checkpoint, is “vpn tu”. There you can see all the tunnels, and delete them.

If you know what caused this, please share :D

 

Tags: , , ,