I have a lan-to-lan tunnel between two sites working well but i have an intermitent problem when we connect more than one person from one site (VPN3020) to the same server in the other site (Checkpoint). The tunnel remains ok but there is no application traffic (in an intermitent way). I saw in the VPN logs that there is a continuous renegotiation of the phase 2 just when the problem appears (in the file attached). This log is repeted the same every second. The tunnel is ok in both sides and there is no problem when is used by only one person.
Is the Network List you are using on the concentrator host based or subnet based? Also do you know if the Checkpoint is mirroring the ACL/Network List exactly? I have seen issues before in the past with Checkpoint if this isn't the case.
In my side (where the clients and Cisco Concentrator are) the network list is subnet based. In the remote side (servers and Checkpoint) the network list is host based. I?m trying to confirm with the other?s site technicians their Network Lists and checking the logs in their firewall. I?ll post again any new information.
Do you have any information about the Checkpoint problems you talk about?
Right there, that is more than likely your problem. The crypto ACLS/Network Lists should be mirrored on both sides. IPSec SA will be setup based on this ACLs and more than likely depending the direction of the flows you might be trying to use a SA that is valid on one end and not valid on the other. First and foremost try to mirror the network lists and see if that resolves your issue.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...