Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

VPN WITH PIX AND FQDN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

VPN WITH PIX AND FQDN

L3 Networker

hello,

I try to migrate a vpn between pix and palo-alto

when I try to generate traffic I can see the following error :

IKE phase-1 negotiation is failed. When pre-shared key is used, peer-ID must be type IP address. Received type FQDN

I understand that my pix need to have a fqdn configured on PALO ALTO in the field -> IKE-GATEWAY

Peer identification -> fqdn(hostnname)

But this is strange because the same configuration between pix and checkpoint works fine without add an fqdn on checkpoint. it is possible on PAlo alto to ignore fqdn like checkpoint??

thanks for your help

5 REPLIES 5

L3 Networker

Hi alle,

checkpoint is not really choosy on building VPNs with others. I suppose, checkpoint tries to identificate with the peer name, and will make the tunnel without this identification, if it dont works.

We have several VPNs with foreign PIXes, but all with "identification none".

greetings

Manfred

hi mhuels,

do you have already create a vpn between pix and palo-alto? it's works fine?

alle schrieb:

hi mhuels,

do you have already create a vpn between pix and palo-alto? it's works fine?

yes we do so. No problems.

regards

manfred

hello,

the problem is solve. pix use isakmp identity hostname

Checkpoint not check this parameters if you want use ip address psk between pix and PALO ALTO

you must use the parameter isakmp identity ip-address on pix

resolved!

  • 3534 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!