Moderators: Asaf Levi

Closed Topic Closed
Go
New
Find
Notify
Tools
-star Rating Rate It!  Login/Join 
Junior Member
Online Status For 86403433
Posted
Hi everybody,

we are trying to implement a HA VPN tunnel between our NGX R60 HFA03 cluster and two VPN1 Edge devices. Unfortunately i wasn´t able to find a guide how to do that.

Both boxes are connected to a router as primary WAN connection and the backup is PPPOE dsl.

I configured both gateways as dynamic ip devices and the topology on both boxes a network object that defines the used network. Each Edge is configured as backup gateway of the other Edge.
I created a star vpn community with the R60 cluster as center gateway and the two edges as satellite gateways.

When i remove the internet connection on the primary box it fails over to the backup and the normal internet traffic is working. But the vpn traffic does not work. In smartview tracker i can see the following log entries:
encryption failure: Wrong peer gateway for decrypted packet (VPN Error code 01).
When i go to smartview monitor and take a look at the tunnels of our cluster i can see a tunnel to the primary and the secondary Edge and both are showing as "up".

Perhaps my configuration is wrong - can anyone help me ?

kind regards,
Alex
 
Posts: 7 | Registered: July 13, 2006Edit or Delete MessageReport This Post
Engineer Level Member
Posted Hide Post
quote:
Originally posted by ASieber:
Hi everybody,

we are trying to implement a HA VPN tunnel between our NGX R60 HFA03 cluster and two VPN1 Edge devices. Unfortunately i wasn´t able to find a guide how to do that.

Both boxes are connected to a router as primary WAN connection and the backup is PPPOE dsl.

I configured both gateways as dynamic ip devices and the topology on both boxes a network object that defines the used network. Each Edge is configured as backup gateway of the other Edge.
I created a star vpn community with the R60 cluster as center gateway and the two edges as satellite gateways.

When i remove the internet connection on the primary box it fails over to the backup and the normal internet traffic is working. But the vpn traffic does not work. In smartview tracker i can see the following log entries:
encryption failure: Wrong peer gateway for decrypted packet (VPN Error code 01).
When i go to smartview monitor and take a look at the tunnels of our cluster i can see a tunnel to the primary and the secondary Edge and both are showing as "up".

Perhaps my configuration is wrong - can anyone help me ?

kind regards,
Alex


Which firmware are you using on the VPN-1 Edge ?
 
Posts: 440 | Registered: June 12, 2006Edit or Delete MessageReport This Post
Junior Member
Online Status For 86403433
Posted Hide Post
firmware version is 6.0.74
 
Posts: 7 | Registered: July 13, 2006Edit or Delete MessageReport This Post
Engineer Level Member
Posted Hide Post
quote:
Originally posted by ASieber:
firmware version is 6.0.74


Please download from the CheckPoint subscription service the latest firmware 6.0.78x
 
Posts: 440 | Registered: June 12, 2006Edit or Delete MessageReport This Post
Junior Member
Online Status For 86403433
Posted Hide Post
6.0.78x is not yet available via Checkpoint subscription dowloads. newest version is 6.0.76x

Alex
 
Posts: 7 | Registered: July 13, 2006Edit or Delete MessageReport This Post
Engineer Level Member
Posted Hide Post
quote:
Originally posted by ASieber:
6.0.78x is not yet available via Checkpoint subscription dowloads. newest version is 6.0.76x

Alex


Please contact me via email for version 6.0.79x
at erez(AT)sofaware.com
 
Posts: 440 | Registered: June 12, 2006Edit or Delete MessageReport This Post
Junior Member
Posted Hide Post
HI

I have a same problem, the version for the 2 vpn1 edge is 6.0.76x, plase help us!!



Regards
 
Posts: 2 | Registered: November 01, 2004Edit or Delete MessageReport This Post
Engineer Level Member
Posted Hide Post
quote:
Originally posted by Adrian:
HI

I have a same problem, the version for the 2 vpn1 edge is 6.0.76x, plase help us!!



Regards


Please contact me via email for version 6.0.79x
at erez(AT)sofaware.com
Please inclose your EBS support agreement.
Version 6.5 will soon be released with many inchantments and with this issue resolved also as in 6.0.79x
 
Posts: 440 | Registered: June 12, 2006Edit or Delete MessageReport This Post
  Powered by Eve Community  

Closed Topic Closed


© Copyright 2006 SofaWare Technologies Ltd.
How To Buy