Hi, i'm having some problem to create an ipsec tunnel with a cisco 837 router and a checkpoint NG fw. I readed a lot of documentations about it, but i cannot establish a tunnel.
In details, during the examination of debug message, i notice that phase 2 end with error.
"phase 2 packet is a duplicate of previous packet"
"retransmit due to retransmit phase 2"
"ignoring retransmission because phase2 node marked dead"
and the messages repeat forever.
It's so stange because if i send packet from checkpoint side, packet enter the router, that decrypt and send real packet to destination.
The destination reply, the packet enter the router but the route does not encrypt it.
I don't use NAT, and i folloewd more or less the docs about creating VPN on cisco site.
Some hints please.