12-29-2005 12:54 AM - edited 02-21-2020 02:10 PM
I am currently at a customer who has problem establishing a stable VPN. The VPN works fo4r some hours and then stopps. The PIX and Checkpoint are synchronized with all parameters for timing of ISAKMP and IPSEC. The PIX log shows with growing occurience event 710003 for ESP access denied by ACL.
01-04-2006 07:17 AM
This message appears when the firewall denies an attempt to connect to the interface service. For example, this message appears (with the service snmp) when the firewall receives an SNMP request from an unauthorized SNMP management station.
Use the show http, show ssh, or show telnet command to verify that the firewall is configured to permit the service access from the host or network. If this message appears frequently, it can indicate an attack.
01-05-2006 04:17 AM
This seemes to be a problem when you try to build a VPN between a checkpoint cluster and a cisco device. If you need to connect Checkpoint and Cisco devices via VPN it is always a good choice (maybe the only) not to use clustered configurations on either side.
Regards,
Norbert
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide