I am configuring a tunnel with some checkpoint firewall.
I have created a phase1 (main mode) SA and no problems here.
I have also established a phase 2 from forti-->checkpoint. (ping wokrs)
however when attempting phase 2 from checkpoint--> forti (pinging to forti' s lan)
I get the infamous:
" Peer' s id payloads do not match local policy."
the forti says " Negotiate SA Error: Peer' s id payloads do not match local policy."
here' s what I' ve configured on the forti. I' d appreciate it if you could help me check my settings and decide where the problem is... thanks!
on the forti (100a BTW):
defined a subnet for my local subnet (subnet_a)
defined a subnet for the remote subnet (subnet_b)
created a main mode VPN with relevant parameters (no problem here)
created a quick mode VPN with relevant paramters. in selectros, I' ve configured subnet_a' s address as source and subnet_b' s address as destination. however subnet B originally has a 30bit SubnetMask but connections were not being accepted until I have configured it under selectors as a 29bit subnet. I do not understand this. also, If I configured it as a 0.0.0.0/0 selector the connection was also accepted with no problems.
this is the connections from fortie-->checkpoint.
I have created a rule on my outbound (internal: subnet_a to wan1: subnet_b) and set the rule to encrypt etc. (rule allows outgoing and incomoing)
this works ok.
I have also created an allow rule (not encrypt) for the wan1 to internal traffic:
wan1: subnet_b to internal: subnet_a, allow.
additionally, I have tried using interface mode (virtual interface), and added a route to the destination (subnet_b) for that to work. the results were basically the same.
any help appreciated. thanks!
-Shay
in interface mode, I have configured 2 " allow" policy for local to remote and remote to local traffic. again, local to remote works but not the other way around.
no matter WHAT I do, when pinging from subnet_b to subnet_a, forti says: " Peer' s id payloads do not match local policy."
also the checkpoint says : notification from peer - " invalid id information"
I thank you very much for your time and attention,
plz helllllp...
-Shay