Got it

Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall

Latest reply: Nov 17, 2021 06:28:26 1296 4 1 0 0

Hello everyone,

Today I will show you how to deal with the failure of constructing an IPSec VPN between Huawei USG6600 and a third-party firewall.

Issue Description:

Customer want to configure IPsec Site to Site VPN between Huawei USG6300 and third-part Firewall, after configuring all required parameters successfully on both ends, But it not working and getting errors after diagnosis.

Product: Huawei USG6600 V500R001C60SPC200

Third-part device: Checkpoint

Alarm Information:

Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall-2690183-1

Handling Process:

1 Compare the ike and IPSec configuration found all of the parameters are the same.

USG6600 configuration as follow:

Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall-2690183-2Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall-2690183-3Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall-2690183-4Check Point Firewall Configuration as follow:

Local Address:2.2.2.2/32

Peer Address:1.1.1.1/32

Authentication Type:Pre-Share-Key

Remote Address Pool:10.91.0.0/16

Local Address Pool:172.18.0.0/16 

IKE Parameter: 

IKE:Version V2

Encryption:3DES

Integity Hash:MD5 

PRF:MD5 

SA Timeout:86400 

IPsec Parameter:

Encryption Mode:Tunnel 

Security Protocol:ESP 

ESP Encryption:3DES

ESP Authentication:MD5 

PFS:None

SA Timeout:By time:3600 Seconds

By Traffic:20971520 KB


 

2 Check the security policy and NAT policy configuration

3 Check the routing table

Root Cause:

ike version and dh group can’t negotiate successfully with third-party firewall


Solution:

Change the IKE version from V2 to V1 and DH group from 14 to 2 between both sides firewall.

Escablish the ipsec vpn between huawei USG6600 and Third-part Firewall-2690183-5


Suggestions:

There may have compatibility issues when establishing IPsec VPN between a third-part firewall.it is recommend using the single algorithm example DES、MD5 without SHA2, and IKE uses V1.


That is all I want to share with you! Thank you!


This article contains more resources

You need to log in to download or view. No account? Register

x

USG6650 fails to negotiate all entries in Encryption Domain (ED), what could be the reason for that?

View more
  • x
  • convention:

Thanks for sharing
View more
  • x
  • convention:

GOOD
View more
  • x
  • convention:

A good article! Thank you for sharing
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.