Lan-to-lan tunnel VPN3020 problem

Unanswered Question
Mar 14th, 2007

I have a lan-to-lan tunnel between two sites working well but i have an intermitent problem when we connect more than one person from one site (VPN3020) to the same server in the other site (Checkpoint). The tunnel remains ok but there is no application traffic (in an intermitent way). I saw in the VPN logs that there is a continuous renegotiation of the phase 2 just when the problem appears (in the file attached). This log is repeted the same every second. The tunnel is ok in both sides and there is no problem when is used by only one person.

Attachment: 
I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
fred.s.mollenkopf Wed, 03/14/2007 - 11:58

Silvestre,

Is the Network List you are using on the concentrator host based or subnet based? Also do you know if the Checkpoint is mirroring the ACL/Network List exactly? I have seen issues before in the past with Checkpoint if this isn't the case.

Please rate any helpful posts

Thanks

Fred

srivero Thu, 03/15/2007 - 01:51

Hi Fred.

In my side (where the clients and Cisco Concentrator are) the network list is subnet based. In the remote side (servers and Checkpoint) the network list is host based. I?m trying to confirm with the other?s site technicians their Network Lists and checking the logs in their firewall. I?ll post again any new information.

Do you have any information about the Checkpoint problems you talk about?

Thanks.

Silvestre.

fred.s.mollenkopf Thu, 03/15/2007 - 07:59

Silvestre,

Right there, that is more than likely your problem. The crypto ACLS/Network Lists should be mirrored on both sides. IPSec SA will be setup based on this ACLs and more than likely depending the direction of the flows you might be trying to use a SA that is valid on one end and not valid on the other. First and foremost try to mirror the network lists and see if that resolves your issue.

Please rate any helpful posts

Thanks

Fred

Actions

This Discussion