Wednesday, January 5, 2011

VPN between Check Point Security Gateway and Cisco Pix fails: "No valid SA"

To resolve this issue proceed as follows:

  1. At the Cisco end, check the Crypto Map settings. Find out from the ACLs if there is a host based VPN setup or a network based VPN setup.

  2. On SmartDashboard, edit the Cisco Interoperable Device object defined on SmartDashboard. Select 'Network Objects > Others > Interoperable Device > VPN > Advanced'. Uncheck 'Support key exchange for subnets'.

    Note: For NGX, select 'Network Objects > Interoperable Device > VPN > Advanced'. Under VPN Tunnel Sharing, select Custom Settings and specify "One VPN tunnel per each pair of hosts".


  3. After completing this procedure, initiate traffic from the source PC. You should be able to see an encrypt in SmartView Tracker.