Tunnel negotiation fails over VPN.

Forum General Networking : VPN, VoIP, Video Conferencing, Remote Connections - Tunnel negotiation fails over VPN.

Tom's Hardware: Over 1.4 million members in 6 different countries available to answer all your high-tech questions. Sign up now! Its free!
Word :    Username :           
 

Hi can you please help me on this issue.



Currently the customer has a number of site to site vpn tunnels, some going to checkpoint nodes and openswan nodes.



One of the vpn termination devices is being changed to a racoon linux based firewall and because of the way the customers checkpoint has been configured there is a mis-match between the peer ID and the peer IP and therefore tunnel negotiation fails. Openswan can be configured to accept a different peer id, which is usually the peer IP but the racoon cannot be reconfigured in this way.





the relevant link, http://www.fw-1.de/aerasec/ng/vpn- [...] teway.html, looks fine and shows how to setup the VPN tunnel but the problem we are having is the checkpoint is configured with the internal IP in the node object and therefore is sending this IP as the Peer ID and the Racoon is expecting the public IP and therefore the tunnel is not being created.



My question is; if we change this internal IP in the node object to the external IP will it then send this external IP as the Peer ID??



Please advice.


Malik.

Sponsored Links
Register or log in to remove.

Since the tunnel isn't working right now anyway, can you give it a try and let us know if it worked?

Reply to thepustule

once again.. a little late :wink:

Reply to lvdax

Did you try to configure manual VPN instead?
I had a problem similar than yours and I solved it by this way.

Reply to erman

once again!!! A little too late... :wink:

Reply to lvdax
Tom's Hardware > Forum > General Networking > VPN, VoIP, Video Conferencing, Remote Connections > Tunnel negotiation fails over VPN.
Go to:

There are 1117 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
Sponsored links
  • Ask the community now
  • Publish
Ad
They won a badge
Join us in greeting them