<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278664#M46470</link>
    <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;I've just run some pings, but I'll check the logs on both Microtik and Checkpoint's end. I'd like to know if my policies, NAT configuration, and topology configuration are correct on checkpoint&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2026 10:20:44 GMT</pubDate>
    <dc:creator>junior_kakou</dc:creator>
    <dc:date>2026-06-18T10:20:44Z</dc:date>
    <item>
      <title>Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278615#M46467</link>
      <description>&lt;P&gt;Hello everyone.&lt;BR /&gt;I’ve been struggling with this architecture for a while now.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schema reseau CIAPOL.png" style="width: 834px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34504i8EB6C3886D477D56/image-size/large?v=v2&amp;amp;px=999" role="button" title="schema reseau CIAPOL.png" alt="schema reseau CIAPOL.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have two MikroTik CCR2004 routers at each site: Site A (head office) and Site B (remote site). Both routers are placed in the DMZ of an Orange fibre box, as shown in the diagram. In addition, the head office is equipped with an up-to-date Check Point 3600 Gaia R82 firewall.&lt;BR /&gt;I have configured a site-to-site IPsec VPN between the head office and the remote site B. The IPsec tunnel is working correctly. The PCs at site A can ping both networks at site B (192.168.1.0/24 and 192.168.2.0/24) and are able to open web pages on the Cloud Key Gen1 at site B.&lt;BR /&gt;PCs at site (B) can ping the servers at site (A) but are unable to open web pages or connect via RDP to the Windows servers at site A.&lt;BR /&gt;When a PC at site B attempts to access a web page on the server located at site (A), it receives the following error&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="page erreur.png" style="width: 411px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34505i2EFF25D3545AD084/image-size/large?v=v2&amp;amp;px=999" role="button" title="page erreur.png" alt="page erreur.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;this is the checkpoint policies settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="policies.png" style="width: 604px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34506i0DFFE5923CD51EE9/image-size/large?v=v2&amp;amp;px=999" role="button" title="policies.png" alt="policies.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;NAT settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT settings.png" style="width: 604px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34507i6D3089295A05C103/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT settings.png" alt="NAT settings.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Routes.png" style="width: 549px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34508iCC230928AF3A6D80/image-size/large?v=v2&amp;amp;px=999" role="button" title="Routes.png" alt="Routes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Routes Settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Routes.png" style="width: 604px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34509i427C754612C2D945/image-size/large?v=v2&amp;amp;px=999" role="button" title="Routes.png" alt="Routes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Topologies stettings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topologies.png" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34510i611014C0D5439C82/image-size/large?v=v2&amp;amp;px=999" role="button" title="Topologies.png" alt="Topologies.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would like you to help me configure the firewall correctly, if it isn’t already, so that the PC at Site B can open and access the resources on the servers at Site A.&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 12:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278615#M46467</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2026-06-17T12:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278637#M46468</link>
      <description>&lt;P&gt;What does it show in the logs on the Check Point end when you attempt to access RDP?&lt;BR /&gt;What troubleshooting have you done on the Microtik side to understand what's going on?&lt;BR /&gt;I suspect you will need to review logs and do a packet capture to see if/how the Microtik is sending the packet to the RDP server.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2026 21:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278637#M46468</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-17T21:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278654#M46469</link>
      <description>&lt;P&gt;Good day!&lt;BR /&gt;&lt;BR /&gt;There are a number of assumptions I may make based on provided information:&lt;/P&gt;&lt;P&gt;1. The only VPN on the path of the problematic connection is Site-to-Site VPN terminated on Micritic routers. The connection doesn't use RemoteAccess VPN mentioned in RoleBased access rules.&lt;/P&gt;&lt;P&gt;2. HTTPS traffic is not dropped by policy because "Empty Response" is still a response which would not be possible if the connection is dropped.&lt;/P&gt;&lt;P&gt;3. The point 2 suggests that 3-way-handshake was completed. However, the connection doesn't establish because some problem related to TLS handshake.&lt;/P&gt;&lt;P&gt;The best guess if we have VPN (transit) + TLS error is packet fragmentation. Please, check MSS settings on &lt;SPAN&gt;MikroTik&amp;nbsp;&lt;/SPAN&gt; side and ensure that it is configured to a proper value for your VPN tunnel settings. You can google for "MSS value calculator" to find a tool to get the values.&lt;/P&gt;&lt;P&gt;In addition, I 100% support the reply from PhoneBoy. An investigation is better to start from Log review.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 07:44:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278654#M46469</guid>
      <dc:creator>Gennady</dc:creator>
      <dc:date>2026-06-18T07:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278664#M46470</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;I've just run some pings, but I'll check the logs on both Microtik and Checkpoint's end. I'd like to know if my policies, NAT configuration, and topology configuration are correct on checkpoint&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 10:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278664#M46470</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2026-06-18T10:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278665#M46471</link>
      <description>&lt;P&gt;Hi Gennady ,&lt;/P&gt;&lt;P&gt;yes, i made changes to the MSS settings on both routers. But i'll start again. thank you&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 10:23:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278665#M46471</guid>
      <dc:creator>junior_kakou</dc:creator>
      <dc:date>2026-06-18T10:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble shouting IPSEC VPN between checkpoint Fw 3600 and Microtik route</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278684#M46473</link>
      <description>&lt;P&gt;The only thing I find "odd" in your configuration is using the gateway object setting for HIDE NAT (versus rules).&amp;nbsp;&lt;BR /&gt;There's a setting in the VPN Community related to NAT also (disable NAT in VPN Community)...what is that set to?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 18:37:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Trouble-shouting-IPSEC-VPN-between-checkpoint-Fw-3600-and/m-p/278684#M46473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-06-18T18:37:33Z</dc:date>
    </item>
  </channel>
</rss>

