[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

(racoon 920) Re: Problems talking with Checkpoint-NG



On Wed, 30 Mar 2005 11:16:00 +0000 (UTC)
hamish@travellingkiwi.com (Hamie) wrote:

> I'm trying to get an ipsec tunnel working between a Linux box 
> (Gentoo - amd64) and a Checkpoint-NG firewall (Nokia platform)
...
> Currently I've got it to the point where it looks like phase-I is 
> almost completing, but it looks like the linux box thinks phase-II
> should start, but for some reason the two ends don't seem to agree
> on what should be happening.

IKE phase 2 ID mismatch, maybe? Have you checked your SPD configuration
against the Checkpoint-NG F/W?

> 2005-03-30 10:12:32: ERROR: ignore information because the message 
>                             has no hash payload.

I think you should examine this packet too.
IKE phase 1 retransmission? well, that's my guess...