cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
498
Views
0
Helpful
2
Replies

VPN between Checkpoint NG Cluster XL and PIX 515E

jsommerfeld
Level 1
Level 1

I am currently at a customer who has problem establishing a stable VPN. The VPN works fo4r some hours and then stopps. The PIX and Checkpoint are synchronized with all parameters for timing of ISAKMP and IPSEC. The PIX log shows with growing occurience event 710003 for ESP access denied by ACL.

2 Replies 2

a-vazquez
Level 6
Level 6

This message appears when the firewall denies an attempt to connect to the interface service. For example, this message appears (with the service snmp) when the firewall receives an SNMP request from an unauthorized SNMP management station.

Use the show http, show ssh, or show telnet command to verify that the firewall is configured to permit the service access from the host or network. If this message appears frequently, it can indicate an attack.

nsteup
Level 1
Level 1

This seemes to be a problem when you try to build a VPN between a checkpoint cluster and a cisco device. If you need to connect Checkpoint and Cisco devices via VPN it is always a good choice (maybe the only) not to use clustered configurations on either side.

Regards,

Norbert