Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Unable to Establish VPN connection through CheckPoint NG firewall

Status
Not open for further replies.

RotaryRocket

Technical User
Jun 24, 2004
2
US
At home I have a CheckPoint NG FP3 Firewall connected to my ISP. I am tryigh to establish a VPN connection to work and I keep getting the following error from my VPN (AT&T RAS) software "Error 118-No response from IPSEC terminator during authentication." See timeline below. It works perfectly fine when I use a linksys router to the ISP. I think I need to set IPSEC pass-through on the Firewall. Can anyone help?

00:05:11.157 Authenticating with the VPN server 00:05:11.227 Action 1 of 1 is 'LogonToIPSecTunnelServer'
00:05:11.267 Configured to allow pass through NAT.
00:05:11.377 Logon request sent to VPN server
00:05:11.397 Wait for asynchronous action to complete.
00:05:11.697 A VPN logon message 1 was received.
00:05:11.738 Accessing digital certificate...
00:05:20.550 A VPN logon message 2 was received.
00:05:20.570 Negotiating encryption keys with VPN server
00:05:24.296 A VPN logon message 3 was received.
00:05:24.316 Authenticating with the VPN server
00:06:05.455 The VPN logon response was received.
00:06:05.565 The Internet address is 192.168.1.4.
00:06:05.705 'LogonToIPSecTunnelServer' failed.
00:06:05.745 FSM error in state 'AuthenticatingTunnel'.
00:06:05.785 !Error 118 No response from IPSEC terminator during authentication. (error 118).
 
What do you FW log say?
Are you allowing the necessary ports/protocols through?

Cheers

Akiwondo (MCSE, CCSA)
 
I have allowed in and out everything and it still does not work. When I use my linksys router only with IPSEC pass thru enabled, it works fine. When I use my CP firewall only, which is doing PATing (hide NAT), and open up the firewall to any to any, the VPN still does not work. My thought is that I need to somehow enable IPSEC pass thru on the CP firewall.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top