Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: [Users] Freeswan + Checkpoint NG NO_PROPOSAL_CHOSEN

From: Christoph Haas <email(at)christoph-haas.de>
Date: Thu May 08 2003 - 16:18:29 EDT

Hi, Jason...

On Thu, May 08, 2003 at 06:05:24PM +0100, Jason Aley wrote:
> I am trying to create an IPSEC tunnel between by Linux firewall running

That works perfectly at our site.

> Despite following the set-up guide verbatum I cannot create the tunnel

The last time I got this message there were problems with the "aggressive mode" setting at the Checkpoint Firewall. Another problem might be the "perfect forward secrecy" setting which must be identical on both the Checkpoint VPN-1 gateway and the FreeS/WAN VPN gateway. On the Checkpoint firewall you need to double-click on the "Encrypt" icon and enter the properties of "IKE" to uncover the PFS flag.

There are however other times when "No proposal chosen" can come up. We had it with our Checkpoint firewall when the topology of the firewall object did not match the interfaces. Checkpoint is garbage in many aspects. This might be one. ;)

> I am able to ping the remote firewall unencrypted so am confident of

Do you need help?X

You would get other error messages in case there were routing errors.

> An example log is included below - Any help on this matter would be

I'm terribly bad at reading the FreeS/WAN logs. So I'm just guessing. :)

 Christoph

-- 
~
~
".signature" [Modified] 3 lines --100%--                3,41         All
_______________________________________________
Users mailing list
Users@lists.freeswan.org
http://lists.freeswan.org/mailman/listinfo/users
Received on Thu May 8 17:31:15 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:30 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library