Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN3000 to CheckpointFW1 tunneling

I have been trying to setup an IPSec Tunnel between VPN3000 and Checkpoint Fw1, but it doesnt seem to work. I have done the setup based on Cisco documents. Also the box to which i am trying to setup the IPSec tunnel with is behind another PIX FW which is between the Checkpoint FW1 and the end machine. Any help is welcomed....

1 REPLY
Cisco Employee

Re: VPN3000 to CheckpointFW1 tunneling

You could turn on the following event logs on the concentrator:

auth

authdbg

ike

ikedbg

ipsec

ipsecdbg

log event 1-9 and see the filterable event log as you establish connection with the checkpoint and see what is not matching in phase 1 and/or 2. Also try to see if you could modify the IKE proposal on the 3000 to use DH group 1 rather 2, as sometimes Checkpoint doesn't want group 2.

103
Views
0
Helpful
1
Replies