Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

vpn between checkpoint and pix

I need to configure a pix to create a vpn tunnel to a Checkpoint firewall. I have configured pix and when I ping from an inside host on the pix to a host on the dmz of CP FW I get MM_NO_STATE when I issue the cmd sh isakmp sa. PIX appears to initiate the vpn tunnel. Any advise.

2 REPLIES
Anonymous
N/A

Re: vpn between checkpoint and pix

need to turn on debug crytpo ipsec/isakmp/engine.

Also try the PIX tsa at :

http://te.cisco.com/SRVS/CGI-BIN/WEBCGI.EXE?New,KB=PIX,dtree=stepbystep

Cisco Employee

Re: vpn between checkpoint and pix

There's good sample configs for both the PIX and CheckPoint here:

http://www.cisco.com/warp/public/110/cp-p.html

If you follow this hen you should be good to go. If it still doesn't work, then as the previous response suggested, we'd need to see the "debug cry isa" and "debug cry sa" output. It's sounds like the PIX is maybe not getting a response from the CheckPoint to its tunnel request, so make sure you have UDP port 500 connectivity between the two devices.

3081
Views
0
Helpful
2
Replies