Firewalls
FW: Stale IKE SA on FW-1 Aug 24 2006 05:51PM
Meidinger Chris (chris meidinger badenIT de) (1 replies)
RE: Stale IKE SA on FW-1 Aug 24 2006 08:24PM
??????? ?? ??? (erezsht netvision net il)
Dear Chris,

Please Try this:

1. Remove the: "Keep Ike SA's" smartDashBoard--> Policy --> Global
Properties --> SmartDashboard Customization --> Configure --> VPN / IKE
Properties --> uncheck "Keep Ike SA's" (make sure that the externally
managed GW guy's do that too)
2. In the cluster object itself: --> advanced --> connection persistency
--> select: rematch all connections.
3. In the cluster object itself: --> VPN --> advanced --> check: perform
organized shutdown (make sure that the externally managed GW guy's do that
too)
4. Install the policy to the cluster.

5. Optionally: [Install R61 Latest HFA (if available) to management
server and cluster.]

If the externally managed gw support's the "send initial contact" then
Under: smart Dashboard--> Policy --> Global Properties --> Smart
Dashboard Customization --> Configure --> VPN / IKE Properties -->
Make sure that the settings in the cluster and the settings in the
remote GW are identical (both should send each other)

This should bring order to chaos in the SA's

Erez Shtang - [ Information Security Consultant ]

_____

From: Meidinger Chris [mailto:chris.meidinger (at) badenIT (dot) de [email concealed]]
Sent: Thursday, August 24, 2006 8:52 PM
To: firewalls (at) securityfocus (dot) com [email concealed]
Subject: FW: Stale IKE SA on FW-1

Hi List,

has anyone ever had an IKE SA that just wouldn't die on a Checkpoint?

The Firewall in question is a (fairly new) R61 clustered on Nokia hardware.

Normally the #vpn tu command should allow SA's to be deleted either singly
or collectively.

I have a stale IKE SA between this gateway and another (externally managed)
gateway that refuses to die. The SA is more than twice as old as the reneg
time, and is just sitting there blocking negotiation of a new one. If I
delete it with #vpn tu absolutely nothing changes and the SA is still
showing in the list.

Have any of you ever seen this before? Does anyone have an idea what I can
do?

I have already tried:

- making changes in encryption in the community settings and publishing the
policy
- deleting the object for the remote gateway and the related rules,
publishing and then recreating them
- every possible #vpn tu command, including deleting ALL IKE+IPSec SA's
- banging my head on the wall

I was even considering booting the firewall, but the SA should be synched on
both so I assume that will be pretty useless as the other node will have the
SA as well.

Thanks in advance for any suggestions, I wasn't able to find *anything* on
google about this type of problem.

Chris Meidinger

HYPERLINK
"http://545293.sigclick.mailinfo.com/sigclick/04070703/080B4E00/030A4E03
/213
21182.jpg"

--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.1.405 / Virus Database: 268.11.5/426 - Release Date: 23/08/2006

--
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.405 / Virus Database: 268.11.5/426 - Release Date: 23/08/2006

<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=windows-1250">

<META HTTP-EQUIV="EXPIRES" CONTENT="0">
<META HTTP-EQUIV="EXPIRESABSOLUTE" CONTENT="Tue, 01 Jun 1999 12:00:00 GMT">
<META HTTP-EQUIV="PRAGMA" CONTENT="NO-CACHE">
<META HTTP-EQUIV="CACHE-CONTROL" CONTENT="PRIVATE">
<META HTTP-EQUIV="CACHE-CONTROL" CONTENT="NO-CACHE">

<meta name=ProgId content=Word.Document>
<meta name=Generator content="Microsoft Word 11">
<meta name=Originator content="Microsoft Word 11">
<link rel=File-List href="cid:filelist.xml (at) 01C6C7D4 (dot) 7663 [email concealed]2100">
<link rel=Edit-Time-Data href="cid:editdata.mso">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<title>FW: Stale IKE SA on FW-1</title>
<!--[if gte mso 9]><xml>
<o:OfficeDocumentSettings>
<o:AllowPNG/>
<o:DoNotRelyOnCSS/>
</o:OfficeDocumentSettings>
</xml><![endif]--><!--[if gte mso 9]><xml>
<w:WordDocument>
<w:Zoom>71</w:Zoom>
<w:DisplayBackgroundShape/>
<w:SpellingState>Clean</w:SpellingState>
<w:GrammarState>Clean</w:GrammarState>
<w:DocumentKind>DocumentEmail</w:DocumentKind>
<w:EnvelopeVis/>
<w:ValidateAgainstSchemas/>
<w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid>
<w:IgnoreMixedContent>false</w:IgnoreMixedContent>
<w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText>
</w:WordDocument>
</xml><![endif]--><!--[if gte mso 9]><xml>
<w:LatentStyles DefLockedState="false" LatentStyleCount="156">
</w:LatentStyles>
</xml><![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
{font-family:Wingdings;
panose-1:5 0 0 0 0 0 0 0 0 0;
mso-font-charset:2;
mso-generic-font-family:auto;
mso-font-pitch:variable;
mso-font-signature:0 268435456 0 0 -2147483648 0;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;
mso-font-charset:0;
mso-generic-font-family:swiss;
mso-font-pitch:variable;
mso-font-signature:1627421319 -2147483648 8 0 66047 0;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{mso-style-parent:"";
margin:0cm;
margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:12.0pt;
font-family:"Times New Roman";
mso-fareast-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
{color:blue;
text-decoration:underline;
text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
{color:purple;
text-decoration:underline;
text-underline:single;}
p
{mso-margin-top-alt:auto;
margin-right:0cm;
mso-margin-bottom-alt:auto;
margin-left:0cm;
mso-pagination:widow-orphan;
font-size:12.0pt;
font-family:"Times New Roman";
mso-fareast-font-family:"Times New Roman";}
span.EmailStyle18
{mso-style-type:personal-reply;
mso-style-noshow:yes;
mso-ansi-font-size:10.0pt;
mso-bidi-font-size:10.0pt;
font-family:Arial;
mso-ascii-font-family:Arial;
mso-hansi-font-family:Arial;
mso-bidi-font-family:Arial;
color:navy;}
span.SpellE
{mso-style-name:"";
mso-spl-e:yes;}
span.GramE
{mso-style-name:"";
mso-gram-e:yes;}
@page Section1
{size:595.3pt 841.9pt;
margin:72.0pt 90.0pt 72.0pt 90.0pt;
mso-header-margin:36.0pt;
mso-footer-margin:36.0pt;
mso-paper-source:0;
mso-gutter-direction:rtl;}
div.Section1
{page:Section1;}
-->
</style>
<!--[if gte mso 10]>
<style>
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-parent:"";
mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
mso-para-margin:0cm;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:10.0pt;
font-family:"Times New Roman";
mso-ansi-language:#0400;
mso-fareast-language:#0400;
mso-bidi-language:#0400;}
</style>
<![endif]--><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>

<body lang=EN-US link=blue vlink=purple style='tab-interval:36.0pt'>

<div class=Section1 dir=RTL>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'>Dear Chris,<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'>Please Try this:<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>1.<span
style='mso-spacerun:yes'>  </span>Remove the: "Keep Ike <span
class=SpellE>SA's</span>"<span style='mso-spacerun:yes'>  </span><span
style='mso-spacerun:yes'> </span><span class=SpellE>smartDashBoard</span></span></font><font
size=2 color=navy face=Wingdings><span style='font-size:10.0pt;font-family:
Wingdings;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bi
di-font-family:
Arial;color:navy;mso-char-type:symbol;mso-symbol-font-family:Wingdings'>
<span
style='mso-char-type:symbol;mso-symbol-font-family:Wingdings'>à</
span></span></font><font
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Policy </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Global Properties </span></font><font size=2 color=navy
face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;

mso-char-type:symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>à</span></span></font><f
ont
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> <span class=SpellE>SmartDashboard</span> Customization </span></font><font
size=2 color=navy face=Wingdings><span style='font-size:10.0pt;font-family:
Wingdings;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bi
di-font-family:
Arial;color:navy;mso-char-type:symbol;mso-symbol-font-family:Wingdings'>
<span
style='mso-char-type:symbol;mso-symbol-font-family:Wingdings'>à</
span></span></font><font
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Configure </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> VPN / IKE Properties </span></font><font size=2 color=navy
face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;

mso-char-type:symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>à</span></span></font><f
ont
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'><span style='mso-spacerun:yes'>  </span>uncheck "Keep Ike
<span class=SpellE>SA's</span>"<span style='mso-spacerun:yes'>  
</span><span style='mso-spacerun:yes'>  </span>(make sure that the
externally managed GW guy's do that too)<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>2.<span
style='mso-spacerun:yes'>  </span><span class=GramE>In</span> the cluster
object itself: </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> advanced </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> connection persistency </span></font><font size=2 color=navy
face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;

mso-char-type:symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>à</span></span></font><f
ont
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> select: rematch all connections.<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>3.<span
style='mso-spacerun:yes'>  </span>In the cluster object itself: </span></font><font
size=2 color=navy face=Wingdings><span style='font-size:10.0pt;font-family:
Wingdings;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bi
di-font-family:
Arial;color:navy;mso-char-type:symbol;mso-symbol-font-family:Wingdings'>
<span
style='mso-char-type:symbol;mso-symbol-font-family:Wingdings'>à</
span></span></font><font
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> VPN </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> advanced </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'><span style='mso-spacerun:yes'>  </span>check:<span
style='mso-spacerun:yes'>  </span>perform organized <span class=GramE>shutdown<span
style='mso-spacerun:yes'>  </span>(</span>make sure that the externally
managed GW guy's do that too)<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>4.<span
style='mso-spacerun:yes'>  </span>Install the policy to the cluster.<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>5. <span
style='mso-spacerun:yes'> </span>Optionally: [Install R61 Latest HFA <span
style='mso-spacerun:yes'>  </span>(if available<span class=GramE>)<span
style='mso-spacerun:yes'>  </span>to</span> management server and cluster.]<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>If the externally
managed <span class=SpellE>gw</span> support's the "send initial contact<span
class=GramE>"<span style='mso-spacerun:yes'>  </span>then</span> <o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'><span
style='mso-spacerun:yes'> </span><span
style='mso-spacerun:yes'> </span><span style='mso-spacerun:yes'> 
</span>Under: <span style='mso-spacerun:yes'>  </span>smart Dashboard</span></font><font
size=2 color=navy face=Wingdings><span style='font-size:10.0pt;font-family:
Wingdings;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bi
di-font-family:
Arial;color:navy;mso-char-type:symbol;mso-symbol-font-family:Wingdings'>
<span
style='mso-char-type:symbol;mso-symbol-font-family:Wingdings'>à</
span></span></font><font
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Policy </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Global Properties </span></font><font size=2 color=navy
face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;

mso-char-type:symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>à</span></span></font><f
ont
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Smart Dashboard Customization </span></font><font size=2
color=navy face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;
mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-fa
mily:
Arial;color:navy;mso-char-type:symbol;mso-symbol-font-family:Wingdings'>
<span
style='mso-char-type:symbol;mso-symbol-font-family:Wingdings'>à</
span></span></font><font
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> Configure </span></font><font size=2 color=navy face=Wingdings><span
style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:Aria
l;
mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;mso-ch
ar-type:
symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:symbol;
mso-symbol-font-family:Wingdings'>à</span></span></font><font size=2
color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> VPN / IKE Properties </span></font><font size=2 color=navy
face=Wingdings><span style='font-size:10.0pt;font-family:Wingdings;mso-ascii-font-family:
Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:navy;

mso-char-type:symbol;mso-symbol-font-family:Wingdings'><span style='mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>à</span></span></font><f
ont
size=2 color=navy face=Arial><span style='font-size:10.0pt;font-family:Arial;
color:navy'> <span style='mso-spacerun:yes'> </span><span
style='mso-spacerun:yes'>  </span><o:p></o:p></span></font></p
>

<p class=MsoNormal dir=LTR style='margin-left:36.0pt'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'><span
style='mso-spacerun:yes'> </span><span
style='mso-spacerun:yes'>   </span>Make sure that the settings in the
cluster and the settings in the remote GW are identical (both should send each
other)<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'>This should bring order
to chaos in the <span class=SpellE>SA's</span><o:p></o:p></span></font></p>

<div>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'>Erez Shtang <span
class=GramE>-<span style='mso-spacerun:yes'>  </span>[</span> Information
Security Consultant ]<o:p></o:p></span></font></p>

<p class=MsoNormal dir=LTR><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p><
/span></font></p>

<div class=MsoNormal align=center dir=LTR style='text-align:center'><font
size=3 face="Times New Roman"><span style='font-size:12.0pt'>

<hr size=2 width="100%" align=center tabindex=-1>

</span></font></div>

<p class=MsoNormal dir=LTR><b><font size=2 face=Tahoma><span style='font-size:
10.0pt;font-family:Tahoma;font-weight:bold'>From:</span></font></b><font

size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> Meidinger
Chris [mailto:chris.meidinger (at) badenIT (dot) de [email concealed]] <br>
<b><span style='font-weight:bold'>Sent:</span></b> Thursday, August 24, 2006
8:52 PM<br>
<b><span style='font-weight:bold'>To:</span></b> firewalls (at) securityfocus (dot) com [email concealed]<br>
<b><span style='font-weight:bold'>Subject:</span></b> FW: Stale IKE SA on FW-1</span></font><o:p></o:p></p>

</div>

<p class=MsoNormal dir=LTR><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>

<p dir=LTR><font size=2 face="Times New Roman"><span style='font-size:10.0pt'>Hi
List,<br>
<br>
has anyone ever had an IKE SA that just wouldn't die on a Checkpoint?<br>
<br>
The Firewall in question is a (fairly new) R61 clustered on Nokia hardware.<br>
<br>
Normally the #vpn tu command should allow SA's to be deleted either singly or
collectively.<br>
<br>
I have a stale IKE SA between this gateway and another (externally managed)
gateway that refuses to die. The SA is more than twice as old as the reneg
time, and is just sitting there blocking negotiation of a new one. If I delete
it with #vpn tu absolutely nothing changes and the SA is still showing in the
list.<br>
<br>
Have any of you ever seen this before? Does anyone have an idea what I can do?<br>
<br>
I have already tried:<br>
<br>
- making changes in encryption in the community settings and publishing the
policy<br>
- deleting the object for the remote gateway and the related rules, publishing
and then recreating them<br>
- every possible #vpn tu command, including deleting ALL IKE+IPSec SA's<br>
- banging my head on the wall<br>
<br>
I was even considering booting the firewall, but the SA should be synched on
both so I assume that will be pretty useless as the other node will have the SA
as well.<br>
<br>
Thanks in advance for any suggestions, I wasn't able to find *anything* on
google about this type of problem.<br>
<br>
Chris Meidinger</span></font><o:p></o:p></p>

</div>

<!--42515046755A-->
<br><br><a href="http://545293.sigclick.mailinfo.com/sigclick/04070703/080B4E00/030
A4E03/21321182.jpg"><img src="http://545293.signature1.mailinfo.com/confirm2.6/04070703/080B4E00/
030A4E03/21321182.jpg" border="0" nosend="1"></a><!--42515046755A//-->
</body>

</html>
<BR>

<P><FONT SIZE=2>--<BR>
No virus found in this incoming message.<BR>
Checked by AVG Free Edition.<BR>
Version: 7.1.405 / Virus Database: 268.11.5/426 - Release Date: 23/08/2006<BR>
</FONT> </P><BR>

<P><FONT SIZE=2>--<BR>
No virus found in this outgoing message.<BR>
Checked by AVG Free Edition.<BR>
Version: 7.1.405 / Virus Database: 268.11.5/426 - Release Date: 23/08/2006<BR>
</FONT> </P>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus