cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
375
Views
0
Helpful
2
Replies

PIX 515 to Checkpoint 4.1 - Only Checkpoint can Initiate Tunnel

bionicjoe
Level 1
Level 1

We have setup a VPN tunnel between our company (PIX 515e) & another company (Checkpoint 4.1) to transfer email. As it stands they can initiate a connection and send us mail, and we can return it for time while the tunnel is up. However we cannot initiate the tunnel on our own. Our mail must wait until they send mail, which creates the tunnel.

I have two possible theories:

1. The lifetimes do not match.

2. They have set up their connection one-way / deny inbound.

Since this forum can't help with #2, please answer this.

Will the connection/tunnel work at all if the lifetimes are incorrect? And would such a config error produce the above situation?

I need to know if the lifetimes are the issue, before I just stab at the problem.

I can't provide my config right now, but will do so if you think it helps.

2 Replies 2

sachinraja
Level 9
Level 9

ya.. lifetimes might be an issue. i had faced such problems before.. make suer you have the same values of configs on lifetime, interesting traffic, SA parameters etc...

Raj

Actually we solved it!!

Finally got on the phone with the other company's service provider, and they debugged while I connected. They had PFS enabled (which shouldn't have been).