Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Julius_Kaiser
Participant
Jump to solution

S2S-IPSEC-Tunnel not comming up without public DNS server configured - why?

Hello Folks,

I have an IPSEC tunnel configured on the given platform (see below). The tunnel peer is defined by IP address, not hostname. Tunnel config is default, Check Point as remote gateway (same platform, firmware etc), perfect forward secrecy with DH Group 2, no NAT.

My problem is: The Tunnel won't come up without a public reachable DNS server configured as the primary DNS server under Device/ DNS/ "Configured DNS Servers".

Does anyone know this kind of behaviour and can provide an explanation, or is this a bug?

Thanks in advance.

Appliance:Check Point 1430 Appliance (gro-aue-fw01)
Security Management:Locally managed
Version (Firmware):R77.20.40 (990171107)
0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

It's possible this is covered by a known limitation listed here: Check Point R77.20 for 600 / 700 / 1100 / 1200R / 1400 Appliance Known Limitations 

Specifically:

01668937

Configuring appliances with a DNS server that does not resolve publich domain names, may cause issues in various features, including timeouts during SIC establishment, log page not being responsive, and more. Make sure to configure DNS servers that can be reached from the appliance.

View solution in original post

2 Replies
PhoneBoy
Admin
Admin

It's possible this is covered by a known limitation listed here: Check Point R77.20 for 600 / 700 / 1100 / 1200R / 1400 Appliance Known Limitations 

Specifically:

01668937

Configuring appliances with a DNS server that does not resolve publich domain names, may cause issues in various features, including timeouts during SIC establishment, log page not being responsive, and more. Make sure to configure DNS servers that can be reached from the appliance.

Julius_Kaiser
Participant

Hello Dameon,

 thanks for your response! I think that's it. The log page not beeing responsive is another phenomenon I noticed when no public DNS was defined.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events