Has Anyone, Ever been able to get a successful site-to-site VPN between Any Checkpoint to Any FortiGate on Any Code???
We' ve got a Checkpoing NG R60 HA Cluster trying to connect to a FortiGate 200A on 3.0 code. We know where the problem lies:
Mismatch on the FortiGate QUICK MODE SELECTOR and what Checkpoint calls the ENCRYPTION DOMAIN. doing a
diag debug en and and a
diag debug app ike 99 shows the problem. The checkpoint wants to show a single source and destination host for the Quick Mode/Encryption Domain, but the FG wants to see a subnet not just a host, because there are multiple hosts that will be using the VPN. In the CLI you can specify groups of host using addresses and groups rather the subnets. This may work, but we have been unsuccessful in our attempts. Has anyone been able to get this to work???
Here' e what we' re seeing on the mismatch when we specify subnets and they specify hosts:
[size=1]
fg-box # diag debug app ike 99
fg-box # 0: comes 110.110.110.254->77.77.77.1,ifindex=2....
0: Exchange=32 Message=0xC59B2C56 len=164
0: checking fg-cp-vpn 77.77.77.1 -> 110.110.110.254:500
0:fg-cp-vpn: phase1 found
0:fg-cp-vpn:1845: received payloads HASH SA NONCE ID ID
0:fg-cp-vpn:1845: responder received first quick-mode message
0:fg-cp-vpn:1850: peer proposal is: peer:110.110.110.34, me:77.77.77.0/255.255.255.0, ports=0/0, protocol=0/0
0:fg-cp-vpn:1850: trying fg-cp-vpn-p2
0:fg-cp-vpn:1850: specified selectors mismatch
fg-cp-vpn: - remote: type=7/7, ports=0/0, protocol=0/0
0:fg-cp-vpn:1850: local=77.77.77.0-77.77.77.255, remote=110.110.110.34-110.110.110.34
0:fg-cp-vpn:1850: - mine: type=7/7, ports=0/0, protocol=0/0
0:fg-cp-vpn:1850: local=77.77.77.0-77.77.77.255, remote=110.110.110.0-110.110.110.255
0:fg-cp-vpn:1850: no matching phase2 found
Negotiate SA Error: Peer' s id payloads do not match local policy. [530]
0:fg-cp-vpn:1845: sending INFO message INVALID_ID_INFORMATION to peer
0:fg-cp-vpn:1845: send IKE Packet(Info Mode):77.77.77.254:500(if2) -> 110.110.110.254:500, len=68
0:fg-cp-vpn:1845: transmitted 68 bytes
fg-cp-vpn: Responder: parsed 110.110.110.254 quick mode message #1 (ERROR)
0:fg-cp-vpn:1850: delete state
[/size]
Most importantly:
[size=1]
0:fg-cp-vpn:1850: local=77.77.77.0-77.77.77.255, remote=
110.110.110.34-110.110.110.34,
0:fg-cp-vpn:1850: - mine: type=7/7, ports=0/0, protocol=0/0
0:fg-cp-vpn:1850: local=77.77.77.0-77.77.77.255, remote=
110.110.110.0-110.110.110.255
0:fg-cp-vpn:1850: no matching phase2 found
Negotiate SA Error: Peer' s id payloads do not match local policy. [530]
[/size]
Any help would be appreciated. Thanks,
John
CISSP, FCNSP
Adv(thanks)ance