|
|||||||||||
|
Re: [Users] Freeswan + Checkpoint NG NO_PROPOSAL_CHOSEN
From: Christoph Haas <email(at)christoph-haas.de>
Date: Thu May 08 2003 - 16:18:29 EDT Hi, Jason...
On Thu, May 08, 2003 at 06:05:24PM +0100, Jason Aley wrote:
That works perfectly at our site. > Despite following the set-up guide verbatum I cannot create the tunnel
The last time I got this message there were problems with the "aggressive mode" setting at the Checkpoint Firewall. Another problem might be the "perfect forward secrecy" setting which must be identical on both the Checkpoint VPN-1 gateway and the FreeS/WAN VPN gateway. On the Checkpoint firewall you need to double-click on the "Encrypt" icon and enter the properties of "IKE" to uncover the PFS flag. There are however other times when "No proposal chosen" can come up. We had it with our Checkpoint firewall when the topology of the firewall object did not match the interfaces. Checkpoint is garbage in many aspects. This might be one. ;) > I am able to ping the remote firewall unencrypted so am confident of
You would get other error messages in case there were routing errors. > An example log is included below - Any help on this matter would be
I'm terribly bad at reading the FreeS/WAN logs. So I'm just guessing. :) Christoph -- ~ ~ ".signature" [Modified] 3 lines --100%-- 3,41 All _______________________________________________ Users mailing list Users@lists.freeswan.org http://lists.freeswan.org/mailman/listinfo/usersReceived on Thu May 8 17:31:15 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:01:30 EDT |
||||||||||
|
|||||||||||