cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3303
Views
0
Helpful
2
Replies

vpn between checkpoint and pix

admin_2
Level 3
Level 3

I need to configure a pix to create a vpn tunnel to a Checkpoint firewall. I have configured pix and when I ping from an inside host on the pix to a host on the dmz of CP FW I get MM_NO_STATE when I issue the cmd sh isakmp sa. PIX appears to initiate the vpn tunnel. Any advise.

2 Replies 2

Not applicable

need to turn on debug crytpo ipsec/isakmp/engine.

Also try the PIX tsa at :

http://te.cisco.com/SRVS/CGI-BIN/WEBCGI.EXE?New,KB=PIX,dtree=stepbystep

gfullage
Cisco Employee
Cisco Employee

There's good sample configs for both the PIX and CheckPoint here:

http://www.cisco.com/warp/public/110/cp-p.html

If you follow this hen you should be good to go. If it still doesn't work, then as the previous response suggested, we'd need to see the "debug cry isa" and "debug cry sa" output. It's sounds like the PIX is maybe not getting a response from the CheckPoint to its tunnel request, so make sure you have UDP port 500 connectivity between the two devices.