cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
352
Views
0
Helpful
3
Replies

Lan-to-lan tunnel VPN3020 problem

srivero
Level 1
Level 1

I have a lan-to-lan tunnel between two sites working well but i have an intermitent problem when we connect more than one person from one site (VPN3020) to the same server in the other site (Checkpoint). The tunnel remains ok but there is no application traffic (in an intermitent way). I saw in the VPN logs that there is a continuous renegotiation of the phase 2 just when the problem appears (in the file attached). This log is repeted the same every second. The tunnel is ok in both sides and there is no problem when is used by only one person.

3 Replies 3

Silvestre,

Is the Network List you are using on the concentrator host based or subnet based? Also do you know if the Checkpoint is mirroring the ACL/Network List exactly? I have seen issues before in the past with Checkpoint if this isn't the case.

Please rate any helpful posts

Thanks

Fred

Hi Fred.

In my side (where the clients and Cisco Concentrator are) the network list is subnet based. In the remote side (servers and Checkpoint) the network list is host based. I?m trying to confirm with the other?s site technicians their Network Lists and checking the logs in their firewall. I?ll post again any new information.

Do you have any information about the Checkpoint problems you talk about?

Thanks.

Silvestre.

Silvestre,

Right there, that is more than likely your problem. The crypto ACLS/Network Lists should be mirrored on both sides. IPSec SA will be setup based on this ACLs and more than likely depending the direction of the flows you might be trying to use a SA that is valid on one end and not valid on the other. First and foremost try to mirror the network lists and see if that resolves your issue.

Please rate any helpful posts

Thanks

Fred

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: