Re: ISA 2006 Site-to-Site VPN to a Netgear FVS114 (IPSec Tunnel)

Tech-Archive recommends: Speed Up your PC by fixing your registry



On Fri, 16 Mar 2007 15:07:14 +0100, Christian <c_mwg@xxxxxx> wrote:
At the moment i´m only getting a "SanityCheckHeader failed errs 4"
whatevere that is?!?!

It sounds like an IKE packet is failing a header sanity check (like packet
length, IKE version or something).

You really need more logging to enable a better diagnosis. The first
question is: where in the negotiations is it failing - Phase-1 or Phase-2?

I'd try enabling IKE debugging on the VPN server. I'm not familiar with
the ISA product, but most IPsec implementations include this ability,
although how to turn it on and where the logs get sent varies.

An alternative is to look at the logs from the client (NetGear), although
generally a VPN server has better logging capabilities than a client.

If you get nowhere with this, then I'd sniff the traffic using wireshark or
similar, and use the packet dump to work out where it is failing.

Roy Hills

.



Relevant Pages

  • Re: WinRoute Pro
    ... the NAT table for I believe. ... packet logging shows some nice information but other times the ... when the connection is torn down from the client side ...
    (comp.security.firewalls)
  • RE: Help with Cisco
    ... clock summer-time EDT recurring ... >logging on the router and added the word log to the end of each line i ... >xxx.xxx.xxx.145, 1 packet ...
    (Security-Basics)
  • RE: frequent vpn tunnel drops
    ... Attached is the log of the concentrator,sometimes it ... ,othertimes it gives duplicate first packet detected. ... > Received remote IP Proxy Subnet data in ID Payload: ... > IKE QM Responder FSM error history (struct ...
    (Security-Basics)
  • Re: iptables and ssh
    ... hmm, I'm logging them, too. ... But you're rejecting them and that is more convenient for the attacker, ... When a packet is dropped or ...
    (Fedora)
  • RE: FW1 External Ruleset validation tools?
    ... rule it trips first. ... In order to be sure to get the packet with ... the firewall logging, one would have to enable logging on all rules. ... > actually look through and ideally the ruleset being hit/missed ...
    (Pen-Test)