Check Point community forum
February 07, 2012, 10:07:10 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
  Home   Forum   Help Search Login Register   **
Welcome, Guest. Please login or register.
Did you miss your activation email?
February 07, 2012, 10:07:10 PM

Login with username, password and session length
Pages: [1]
  Print  
Author Topic: "Cannot identify peer for encrypted connection"  (Read 2548 times)
gsandorx
Newbie
*
Posts: 2


« on: September 16, 2009, 09:28:04 PM »


Hi,
I have to set up a site-to-site VPN between my CP gateway, and a FORTIGATE 200A.
When I ping one of the remote internal addresses ,SmartView Tracker is reports me the following error:
"encryption failure: Cannot identify peer for encrypted connection (VPN error 01)"
When I ping from the other side (the remote site), i get the same message but with (VPN error 04).

I'm using NG R55 with AI HFA20.

Any ideas?

Thanks,
Sandor
Logged
juve
Administrator
Jr. Member
*****
Posts: 92


« Reply #1 on: September 17, 2009, 03:09:20 PM »

Are you using simplified mode or traditional mode policies? If using traditional mode, double-click the encrypt on the rule and make sure the correct gateway is assigned as peer. Also check that routing is set towards the external gateway for the VPN subnet and that the encryption domain of the remote firewall is setup correctly on the interoperable device.
Logged
gsandorx
Newbie
*
Posts: 2


« Reply #2 on: September 17, 2009, 06:11:50 PM »

i'm using traditional-mode.

>> "Also check that routing is set towards the external gateway for the VPN subnet"

i don't get this. do you mean that i have to update my Fw's routing table to contains the remote VPN domain. i mean, if the remote domain is 192.168.1.0/24 i have to have a route to reach that subnet???
Logged
juve
Administrator
Jr. Member
*****
Posts: 92


« Reply #3 on: September 18, 2009, 08:52:05 AM »

you don't need an explicit route, unless you have a more general route pointing towards the inside or dmz. If you have a route sending 192.168.0.0/16 towards the lan, the firewall thinks 192.168.1.0/24 is also on the lan and this has an impact on encryption. If you don't have any route in the routing table, the default gateway is selected anyway.
Logged
Pages: [1]
  Print  
 
Jump to:  

Recent
[December 20, 2011, 07:35:00 AM]

[August 11, 2011, 07:07:19 AM]
Members
Total Members: 226
Latest: mkouzuma
Stats
Total Posts: 183
Total Topics: 76
Online Today: 10
Online Ever: 21
(February 06, 2009, 02:31:43 PM)
Users Online
Users: 0
Guests: 11
Total: 11
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!