Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN between Checkpoint NG Cluster XL and PIX 515E

I am currently at a customer who has problem establishing a stable VPN. The VPN works fo4r some hours and then stopps. The PIX and Checkpoint are synchronized with all parameters for timing of ISAKMP and IPSEC. The PIX log shows with growing occurience event 710003 for ESP access denied by ACL.

2 REPLIES
Silver

Re: VPN between Checkpoint NG Cluster XL and PIX 515E

This message appears when the firewall denies an attempt to connect to the interface service. For example, this message appears (with the service snmp) when the firewall receives an SNMP request from an unauthorized SNMP management station.

Use the show http, show ssh, or show telnet command to verify that the firewall is configured to permit the service access from the host or network. If this message appears frequently, it can indicate an attack.

New Member

Re: VPN between Checkpoint NG Cluster XL and PIX 515E

This seemes to be a problem when you try to build a VPN between a checkpoint cluster and a cisco device. If you need to connect Checkpoint and Cisco devices via VPN it is always a good choice (maybe the only) not to use clustered configurations on either side.

Regards,

Norbert

246
Views
0
Helpful
2
Replies