Nokia IP350  Firewall
Problem for Nokia IP350 (NBB335F000) Firewall

Site VPN failed between Checkpoint AI R55 gateways




By Mini Me - usenet poster

" "
Hi All,

We are configuring new firewall in our local and remote office.
Check point AI R55 with HFA-02
Nokia IPSO 3.7.1
Windows 2000 SP4

Local vpn-1 pro enforcement module - Nokia IP 350
Local checkpoint express smart center server - Windows 2000
(Statically NATed and enabled control connection located in LAN)

Remote vpn-1 pro enforcement module - Nokia IP 130

We can push the policies no problem. But we are not getting log from
remote module.
Site vpn also failed even the time sync is correct.
We have the following error in local log file - IKE: phase 1 received
notification from peer, invalid certificate.
Remote firewall module log shows the following error message.
IKE : Main mode validation timed out.

Any help would be greatly appreciated.

Thanks & Regards
Sekar.

Solution #1

posted on May 27, 2006
Not Rated)

Charlie

Rank: Apprentice 
Rating: 0%, 0 votes
Hi,
My problem has been resolved by doing the following.

1) Install a NAT rule on the Remote module
* Original Source: Remote module
* Original Destination: INTERNAL IP address of the mgmt server
* Original Service: ANY
* Translated Source: original
* Translated Destination: EXTERNAL IP address of the mgmt server
* Transalted servcie: original

2) Disable client side NATting for manual NAT rules
Policy - Global properties - NAT - Uncheck 'Translate destination on client side'
Was this helpful?
Yes
No

Solution #2

posted on May 27, 2006
Not Rated)

Rachel007

Rank: Apprentice 
Rating: 0%, 0 votes
(Richard H Miller) wrote in message <>...

1. VPN comuunity rule allows from any and all service. Installed both
firewalls
2. I do not have export option since both firewalls are internally
managed
3. My first rule allows any service from remote firewall to management
server

My setup is like this,
Local Firewall
Nokia IP 350 - Enforcement Module (IPSO 3.7.1) (CP AI - R55 with
HFA-2)
Int interface - 10.65.16.1
DMZ interface - 10.65.8.98
Ext interface - 209.20.128.60.198

Local Managment server
Windows 2000 sp4 - Smart center (CP AI - R55 with HFA-2)
IP address - 10.65.16.19 (Enabled static nat with ip address -
209.20.128.199) (Also enabled the control connection)

Remote firewall
Nokia IP 130 - Enforcement Module (IPSO 3.7.1) (CP AI - R55 with
HFA-2)
Int interface - 10.86.16.1
DMZ interface - 10.86.6.2
Ext interface - 211.158.158.220

First rule allows remote firewall to access management server (Service
- ANY)
also VPN community rule for site to site vpn (service - ANY)
Remote gateway & local gateway is the member of community.
Mangement server is also a Certificate authority. (Default)

I can do SIC and push policies to remote firewall. But when I try to
ping remote internal ip address, It is trying to establish the tunnel.
But error msg shows ( IKE phase 1 - recieved notification from
peer.invalid certificate) Even i am not receiving log from remote
firewall.
Both firewalls hosts file has the name and public IP address of
firewall and management server. So no problem with name resolution.
Date & time is correct in firewalls and management server.
Was this helpful?
Yes
No

Solution #3

posted on May 27, 2006
Not Rated)

pandamama

Rank: Apprentice 
Rating: 0%, 0 votes
turn on VPN debug at the command prompt("VPN debug on")... then read
your logs.


<>...

before any encryption rules
remote box and setup the appropriate
vpn define as a cert]. Is there a
with the management server

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (#).
Version: 6.0.650 / Virus Database: 416 - Release Date: 4/4/2004
Was this helpful?
Yes
No

Solution #4

posted on May 27, 2006
Not Rated)

Grant

Rank: Apprentice 
Rating: 0%, 0 votes
: No problem with SIC, In fact i can push the policies without any problem.

: > SIC? has it been established between the FW and Nokia?
: >
: >
: >
: > > Hi All,
: > >
: > > We are configuring new firewall in our local and remote office.
: > > Check point AI R55 with HFA-02
: > > Nokia IPSO 3.7.1
: > > Windows 2000 SP4
: > >
: > > Local vpn-1 pro enforcement module - Nokia IP 350
: > > Local checkpoint express smart center server - Windows 2000
: > > (Statically NATed and enabled control connection located in LAN)
: > >
: > > Remote vpn-1 pro enforcement module - Nokia IP 130
: > >
: > > We can push the policies no problem. But we are not getting log from
: > > remote module.
: > > Site vpn also failed even the time sync is correct.
: > > We have the following error in local log file - IKE: phase 1 received
: > > notification from peer, invalid certificate.
: > > Remote firewall module log shows the following error message.
: > > IKE : Main mode validation timed out.

Ok

1) Did you define a rule in both modules policy to allow IKE. This will be before any encryption rules
and allows the two module to exchange key information

2) Did you export your CA information and install a certificate on the remote box and setup the appropriate
trust for the cert's [From the error message it looks like you have the vpn define as a cert]. Is there a
reson to use this instead of shared secret?

3) Have you setup a rule to allow the enforcement module to completly talk with the management server

Richard H. Miller, MCSE, CCSE+
Information Security Manager
Information Technology Security and Compliance
Information Technology - Baylor College of Medicine
Was this helpful?
Yes
No

Solution #5

posted on May 27, 2006
Not Rated)

Phoebe

Rank: Apprentice 
Rating: 0%, 0 votes
If you are using pre-shared secret; try this suggested solution.

Re-enter the preshared secrets for the firewall objects involved in VPN.
This clearly applies only when pre-shared secrets are being used and may not
always be the solution to the problem

...
<>...

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (#).
Version: 6.0.650 / Virus Database: 416 - Release Date: 4/4/2004
Was this helpful?
Yes
No

Solution #6

posted on May 27, 2006
Not Rated)

Perkins

Rank: Apprentice 
Rating: 0%, 0 votes
No problem with SIC, In fact i can push the policies without any problem.
Was this helpful?
Yes
No

Solution #7

posted on May 27, 2006
Not Rated)

Cornish

Rank: Apprentice 
Rating: 0%, 0 votes
SIC? has it been established between the FW and Nokia?

...

---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (#).
Version: 6.0.648 / Virus Database: 415 - Release Date: 3/31/2004
Was this helpful?
Yes
No

Popular Solutions for Nokia IP350 Firewall


Questions and Unsolved Problems for Nokia IP350 Firewall


Do you recommend Nokia IP350 (NBB335F000) Firewall?
Answer

Answer
i put in my code to run streaming for the ps3 and i get an error message saying that my internet... (More)

Answer
Firewall/ Router Limiting Network Traffic.you need to open up a port so other can connect to you ... (More)

Answer
why my laptop has a problem going shut down when i put a cd to watch movie

Answer
Cant get a signal on xbox live via a D-link wireless router &amp; Virgib broadband

Answer
I just got this IP350 from eBay. When I powered it up, I did not get anything on the cosnole. How do... (More)


Didn't find what you were looking for?

Describe your problem:

Select a Category:







Ask our Experts

 

Solve Your Problem Now!
Chat Live with an Expert
Chat Now
Browse popular Problems
More Common Problems
Most Common Problems for:
For Nokia IP350 Firewall:

Top Firewall Experts

Rank: Guru Guru  

Solutions: 3630
Member Since: June 2007

Experience: Semi retired, was network administrator, proficient with hardware, software, networks, CAD systems

Ask Me
Find more Firewall Experts

Top Computer & Laptop Repair

(513) 874-3306
We fix and repair laptop motherboard no video, no...
LaptopOnCall Inc.

(877) 934-6198
Send your laptop to us and we will diagnose the...
A+ Rated Oceanside Computer Sales & Service, LLC


       
Solve Your Problem Now!
Chat Live with an Expert
Chat Now

X
Continue
When the original poster rates a solution that was given to his own problem, that rating is locked!
X

Are you sure the solution content is Inappropriate?
   
Tech buddies can communicate directly to answer questions. Become a Tech Buddy and have direct access to your favorite expert for FREE!
Insert Link
Insert Image
Insert You-Tube clip
Insert List
Insert List
Spell Check

What is this?



Select