|
CAUSE |
During IKE Quick Mode Exchange, the VPN daemon negotiates IPSec Security Associations (SA's) with the VPN partner site. If negotiations fail and the exchange does not complete, the VPN daemon has no IPSec SA's to send to the Security Gateway kernel. The Security Gateway daemon expires the running VPN's state tables entries or does not start a new VPN, since it did not receive the updated IPSec SA's. The expiration triggers the "Packet is dropped because there is no valid SA" error message. VPN between Check Point Security Gateway and Cisco Pix fails because Cisco Tunnel Sharing is configured for host based VPN, while Check Point Tunnel Sharing is usually configured for network based VPN. |
SOLUTION |
To resolve this issue proceed as follows:
|
Labels
- Cheat Sheets (7)
- Checkpoint (159)
- Cisco (24)
- Commands (5)
- Fortigate (2)
- Frame-Relay (9)
- Linux (3)
- Netscaler (29)
- Netscreen (2)
- Nokia (7)
- UNIX (2)
Live Traffic
VPN between Check Point Security Gateway and Cisco Pix fails: "No valid SA"
6/25/2011 09:36:00 AM
Posted by MK | Filed Under Checkpoint | 0 Comments
Comments
Search This Blog
Blog Archive
-
▼
2011
(107)
-
▼
June
(49)
- Configuring controller E1
- Autonegotiation Valid Configuration
- Hardware Troubleshooting for Cisco 12000 Series In...
- troubleshooting high CPU utilization
- NetScaler Password Recovery Procedure
- Configuring DNS
- Configuring Link Aggregate Channels
- To configure a VLAN by using the NetScaler command...
- Configuring Network Interfaces
- Enabling and Disabling MAC-Based Forwarding Mode
- Enabling and Disabling Layer 2 or 3 Mode
- Binding the SSL Policy to an SSL Vserver
- Creating SSL Policies
- Creating an SSL Action to Enable OWA Support
- Binding an SSL Certificate Key Pair to the Vserver
- Adding a Certificate Key Pair
- Binding Services to the SSL Vserver
- Adding an SSL-Based Vserver
- Securing Load Balanced Traffic by Using SSL
- Binding a Compression Policy to a Vserver
- Configuring Services to Compress Data
- Enabling Compression
- Configuring Backup Vservers
- Configuring URL Redirection
- How To Perform a SecurePlatform Firewall Health Ch...
- VPN between Check Point Security Gateway and Cisco...
- SmartView Tracker allows a maximum of 0 windows
- What is ike.elg?
- How can I troubleshoot Cisco to Check Point VPN
- How to increase sizes of buffer / ring descriptor ...
- The CPinfo utility
- What information is required to troubleshoot the V...
- Enabling IKE and VPN debugging
- How do I run full blown VPN debug on gateway for t...
- How to generate a valid ike debug, vpn debug and f...
- The reason why we need LDAP profiles
- How To Perform a SecurePlatform Firewall Health Ch...
- Checkpoint - Log File Corrupted
- The netstat Command
- VI - Cheat Sheet
- Checkpoint - Critical error messages and logs
- TCP DUMP
- Checkpoint : Unwanted Services : Save Memory
- Checkpoint Commands - In depth - tHEY dONT liKE BU...
- Path of Database Revision Controls
- NTP in Splat
- Upgrade and Roadmap Diagrams Now Include R75.10
- CPX 2011: Security Gateways in the data center
- Advanced migration of Provider-1 R7x
-
▼
June
(49)
Post a Comment