cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
608
Views
0
Helpful
1
Replies

Issues with site to site VPN Phase 1 - no proposal messages

carl_townshend
Spotlight
Spotlight

Hi All

I am having issues bringing up a vpn between an ASA and a Checkpoint firewall.

I am using the normal settings that we use to connect on our others but this one fails to come up.

I can see all the phase 1 proposals sent through, approx 10 sets, but the Checkpoint seems to not agree on them and sends a no proposal chosen message back to the ASA, gets stuck on MM1 message.

One thing to note is that the Checkpoint is in Russia, do Russia block any VPN protocols?

Any ideas why it isn't working?

cheers

1 Reply 1

johnlloyd_13
Level 9
Level 9

hi,

can both VPN peers ping each others' public WAN/'outside' IP?

can you post a sanitized config from both ASA and CP FW?

try to do some IKE phase 1 debug and post a sanitize output.

Review Cisco Networking products for a $25 gift card